Skip to content

Refresh agentic workflows to gh-aw v0.83.5 - #131996

Merged
vitek-karas merged 3 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-refresh-gh-aw-compiler
Aug 10, 2026
Merged

Refresh agentic workflows to gh-aw v0.83.5#131996
vitek-karas merged 3 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-refresh-gh-aw-compiler

Conversation

@vitek-karas

@vitek-karasvitek-karas commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

  • Upgrade all six agentic workflows from gh-aw v0.82.6 to the latest stable release, v0.85.4.
  • Regenerate the six workflow lock files and shared action pins with --schedule-seed dotnet/runtime.
  • Enable future workflows to use safe-output data payloads to store workflow-related metadata on issues and pull requests in a standard format.
  • Align the holistic-review trusted configuration paths with the engines supported by v0.85.4, removing the retired Crush, Antigravity, and OpenCode paths.
  • Accept v0.85.4's generated-surface updates: remove the unused agentics maintenance workflow because no workflow configures expiration, and remove the ineffective merge=ours lock-file attribute.

Validation

  • All six workflows compile successfully with gh-aw v0.85.4.
  • gh aw compile --schedule-seed dotnet/runtime --no-emit --validate --zizmor --poutine
  • A second full compilation produced an identical diff.

Note

This PR description was generated by GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI lite review requested due to automatic review settings August 7, 2026 13:05
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR refreshes the repository’s agentic GitHub Actions workflows to gh-aw v0.83.5, updating pinned action SHAs/container images and incorporating newer safe-outputs / MCP-gateway wiring. The changes primarily touch generated “*.lock.yml” workflows plus the generated agentic maintenance workflow and the shared gh-aw action pin map.

Changes:

  • Bump gh-aw compiler references across the lock workflows to v0.83.5 (and update associated action SHAs, firewall/MCP images, Copilot CLI version, etc.).
  • Update workflow runtime behavior around MCP gateway startup / docker socket group resolution, safe outputs processing, and additional error/guard outputs.
  • Regenerate the agentic maintenance workflow and update the gh-aw actions pin map.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
.github/workflows/holistic-review.lock.ymlUpdates pinned gh-aw/actions/containers and refactors MCP gateway + safe outputs plumbing for the holistic review workflow.
.github/workflows/closed-issue-reference-check.lock.ymlSame refresh for the closed-issue reference check workflow, including updated MCP server container/features and safe outputs processing.
.github/workflows/ci-failure-scan.lock.ymlSame refresh for the CI failure scan workflow, including updated pins and MCP gateway configuration.
.github/workflows/agentics-maintenance.ymlRegenerated maintenance workflow for v0.83.5; splits “close expired” operations into discussions/issues/PR jobs and updates action pins.
.github/aw/actions-lock.jsonUpdates the pinned github/gh-aw-actions/* entries to v0.83.5 SHAs.

Comment thread.github/workflows/holistic-review.lock.yml Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI review requested due to automatic review settings August 7, 2026 15:33

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated no new comments.

@PureWeenPureWeen left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we bump this to v0.85.4 instead? It was the latest stable release before this PR opened, while v0.83.5 is marked prerelease upstream.

It looks like v0.83.5 was selected because it introduced the safe-output metadata channel this PR needs, but I could not find a compatibility reason to stop there. Regenerating with v0.85.4 would also pick up the security hardening and fixes since then.

Note

This review comment was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI review requested due to automatic review settings August 9, 2026 15:03

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 10 out of 10 changed files in this pull request and generated 2 comments.

Suppressed comments (2)

.github/workflows/holistic-review.md:82

  • The PR title/description says the workflows are being refreshed to gh-aw v0.83.5, but this workflow source now states the recognized agent config paths are for gh-aw v0.85.4. The lock workflows in this PR also advertise they were generated with v0.85.4, so the PR metadata and the pinned compiler version appear out of sync.

Please reconcile by either updating the PR title/description to v0.85.4, or by pinning/regenerating the workflows with v0.83.5 so the version claims match across metadata, source .md, and .lock.yml files.

 # These are the agent configuration paths recognized by gh-aw v0.85.4.
# Re-audit this list whenever the pinned gh-aw compiler version changes.
trusted_agent_folders=(

.gitattributes:86

  • Removing merge=ours from the lock-workflow attribute will make Git merges try to merge the generated .github/workflows/*.lock.yml files normally, which can create frequent conflicts/churn for auto-generated content. If these files are intended to remain generator-owned, keep the merge strategy override to avoid noisy merges.
.github/workflows/*.lock.yml linguist-generated=true

Comment thread.github/workflows/closed-issue-reference-check.lock.yml
Comment thread.github/workflows/breaking-change-doc.lock.yml
@vitek-karas

Copy link
Copy Markdown
MemberAuthor

@PureWeen thanks for the feedback - I updated the PR to use the newest released version. Can you please take another look and possibly approve (need an approval for merge).

@vitek-karas
vitek-karas merged commit 1e4f4bc into dotnet:mainAug 10, 2026
143 of 145 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-refresh-gh-aw-compiler branch August 10, 2026 13:11
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 11, 2026
jtschuster pushed a commit to jtschuster/runtime that referenced this pull request Aug 11, 2026
## Summary
- Upgrade all six agentic workflows from gh-aw v0.82.6 to the latest
stable release, v0.85.4.
- Regenerate the six workflow lock files and shared action pins with
`--schedule-seed dotnet/runtime`.
- Enable future workflows to use safe-output `data` payloads to store
workflow-related metadata on issues and pull requests in a standard
format.
- Align the holistic-review trusted configuration paths with the engines
supported by v0.85.4, removing the retired Crush, Antigravity, and
OpenCode paths.
- Accept v0.85.4's generated-surface updates: remove the unused agentics
maintenance workflow because no workflow configures expiration, and
remove the ineffective `merge=ours` lock-file attribute.
## Validation
- All six workflows compile successfully with gh-aw v0.85.4.
- `gh aw compile --schedule-seed dotnet/runtime --no-emit --validate
--zizmor --poutine`
- A second full compilation produced an identical diff.
> [!NOTE]
> This PR description was generated by GitHub Copilot.
---------
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
vitek-karas added a commit that referenced this pull request Aug 12, 2026
## Summary
Several agentic workflows used HTML comments as machine-readable
markers. That does not work: gh-aw removes agent-provided HTML comments
when it sanitizes safe-output text. The comments were therefore not
present in the posted issue or PR content, so later workflow runs could
not reliably recognize earlier work. On #128405, this allowed
`ci-failure-fix` to post two different handoff comments.
This change replaces those comments with markers that survive
publishing:
- `safe-outputs.data` where the output type supports structured data.
- Stable visible Markdown fields where structured data is not supported
or would break the required content format.
Existing visible markers are still recognized so older workflow output
continues to work.
## Changes by workflow
- **`ci-failure-fix`**: Adds structured identifiers to fix PRs,
help-wanted PRs, and handoff comments. Deduplication now checks every
comment instead of assuming comments are at a fixed position, and it
still recognizes older visible markers.
- **`closed-issue-reference-check`**: Adds structured identifiers to
advisory comments. The pre-check skips issues that contain either the
new structured marker or the older workflow-specific marker and advisory
heading.
- **`ci-failure-scan`**: Moves KBE authoring guidance and the
verified-match count into collapsed, clearly labeled sections. KBE
bodies still contain exactly one JSON block, as required by Build
Analysis.
- **`ci-failure-scan-feedback`**: Reads the new `ci-failure-fix`
identifiers while keeping compatibility with older markers. Its tracker
identity and window are stored in a collapsed visible section, and
tracker updates explicitly replace the body instead of appending to it.
The shared workflow guidance now documents that HTML comments are
removed and explains when to use structured data or visible fields. The
affected generated workflows were refreshed with gh-aw v0.83.5.
## Related change
#131996 is the repository-wide mechanical refresh to gh-aw v0.83.5. This
PR contains the workflow behavior and authoring changes, and regenerates
the affected workflows with the same compiler version.
## Validation
- Compiled and validated the affected workflows with gh-aw v0.83.5.
- Ran poutine and zizmor on the changed workflows.
- Checked the KBE templates keep exactly one JSON block and contain the
required collapsed guidance and metadata.
> [!NOTE]
> This PR description was generated with GitHub Copilot.
---------
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skillsAgent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@vitek-karas@jkoritzinsky@PureWeen@kotlarmilos
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Refresh agentic workflows to gh-aw v0.83.5 by vitek-karas · Pull Request #131996 · dotnet/runtime · GitHub
Skip to content

Refresh agentic workflows to gh-aw v0.83.5 - #131996

Merged
vitek-karas merged 3 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-refresh-gh-aw-compiler
Aug 10, 2026
Merged

Refresh agentic workflows to gh-aw v0.83.5#131996
vitek-karas merged 3 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-refresh-gh-aw-compiler

Conversation

@vitek-karas

@vitek-karasvitek-karas commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

  • Upgrade all six agentic workflows from gh-aw v0.82.6 to the latest stable release, v0.85.4.
  • Regenerate the six workflow lock files and shared action pins with --schedule-seed dotnet/runtime.
  • Enable future workflows to use safe-output data payloads to store workflow-related metadata on issues and pull requests in a standard format.
  • Align the holistic-review trusted configuration paths with the engines supported by v0.85.4, removing the retired Crush, Antigravity, and OpenCode paths.
  • Accept v0.85.4's generated-surface updates: remove the unused agentics maintenance workflow because no workflow configures expiration, and remove the ineffective merge=ours lock-file attribute.

Validation

  • All six workflows compile successfully with gh-aw v0.85.4.
  • gh aw compile --schedule-seed dotnet/runtime --no-emit --validate --zizmor --poutine
  • A second full compilation produced an identical diff.

Note

This PR description was generated by GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI lite review requested due to automatic review settings August 7, 2026 13:05
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR refreshes the repository’s agentic GitHub Actions workflows to gh-aw v0.83.5, updating pinned action SHAs/container images and incorporating newer safe-outputs / MCP-gateway wiring. The changes primarily touch generated “*.lock.yml” workflows plus the generated agentic maintenance workflow and the shared gh-aw action pin map.

Changes:

  • Bump gh-aw compiler references across the lock workflows to v0.83.5 (and update associated action SHAs, firewall/MCP images, Copilot CLI version, etc.).
  • Update workflow runtime behavior around MCP gateway startup / docker socket group resolution, safe outputs processing, and additional error/guard outputs.
  • Regenerate the agentic maintenance workflow and update the gh-aw actions pin map.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
.github/workflows/holistic-review.lock.ymlUpdates pinned gh-aw/actions/containers and refactors MCP gateway + safe outputs plumbing for the holistic review workflow.
.github/workflows/closed-issue-reference-check.lock.ymlSame refresh for the closed-issue reference check workflow, including updated MCP server container/features and safe outputs processing.
.github/workflows/ci-failure-scan.lock.ymlSame refresh for the CI failure scan workflow, including updated pins and MCP gateway configuration.
.github/workflows/agentics-maintenance.ymlRegenerated maintenance workflow for v0.83.5; splits “close expired” operations into discussions/issues/PR jobs and updates action pins.
.github/aw/actions-lock.jsonUpdates the pinned github/gh-aw-actions/* entries to v0.83.5 SHAs.

Comment thread.github/workflows/holistic-review.lock.yml Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI review requested due to automatic review settings August 7, 2026 15:33

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated no new comments.

@PureWeenPureWeen left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we bump this to v0.85.4 instead? It was the latest stable release before this PR opened, while v0.83.5 is marked prerelease upstream.

It looks like v0.83.5 was selected because it introduced the safe-output metadata channel this PR needs, but I could not find a compatibility reason to stop there. Regenerating with v0.85.4 would also pick up the security hardening and fixes since then.

Note

This review comment was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI review requested due to automatic review settings August 9, 2026 15:03

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 10 out of 10 changed files in this pull request and generated 2 comments.

Suppressed comments (2)

.github/workflows/holistic-review.md:82

  • The PR title/description says the workflows are being refreshed to gh-aw v0.83.5, but this workflow source now states the recognized agent config paths are for gh-aw v0.85.4. The lock workflows in this PR also advertise they were generated with v0.85.4, so the PR metadata and the pinned compiler version appear out of sync.

Please reconcile by either updating the PR title/description to v0.85.4, or by pinning/regenerating the workflows with v0.83.5 so the version claims match across metadata, source .md, and .lock.yml files.

 # These are the agent configuration paths recognized by gh-aw v0.85.4.
# Re-audit this list whenever the pinned gh-aw compiler version changes.
trusted_agent_folders=(

.gitattributes:86

  • Removing merge=ours from the lock-workflow attribute will make Git merges try to merge the generated .github/workflows/*.lock.yml files normally, which can create frequent conflicts/churn for auto-generated content. If these files are intended to remain generator-owned, keep the merge strategy override to avoid noisy merges.
.github/workflows/*.lock.yml linguist-generated=true

Comment thread.github/workflows/closed-issue-reference-check.lock.yml
Comment thread.github/workflows/breaking-change-doc.lock.yml
@vitek-karas

Copy link
Copy Markdown
MemberAuthor

@PureWeen thanks for the feedback - I updated the PR to use the newest released version. Can you please take another look and possibly approve (need an approval for merge).

@vitek-karas
vitek-karas merged commit 1e4f4bc into dotnet:mainAug 10, 2026
143 of 145 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-refresh-gh-aw-compiler branch August 10, 2026 13:11
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 11, 2026
jtschuster pushed a commit to jtschuster/runtime that referenced this pull request Aug 11, 2026
## Summary
- Upgrade all six agentic workflows from gh-aw v0.82.6 to the latest
stable release, v0.85.4.
- Regenerate the six workflow lock files and shared action pins with
`--schedule-seed dotnet/runtime`.
- Enable future workflows to use safe-output `data` payloads to store
workflow-related metadata on issues and pull requests in a standard
format.
- Align the holistic-review trusted configuration paths with the engines
supported by v0.85.4, removing the retired Crush, Antigravity, and
OpenCode paths.
- Accept v0.85.4's generated-surface updates: remove the unused agentics
maintenance workflow because no workflow configures expiration, and
remove the ineffective `merge=ours` lock-file attribute.
## Validation
- All six workflows compile successfully with gh-aw v0.85.4.
- `gh aw compile --schedule-seed dotnet/runtime --no-emit --validate
--zizmor --poutine`
- A second full compilation produced an identical diff.
> [!NOTE]
> This PR description was generated by GitHub Copilot.
---------
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
vitek-karas added a commit that referenced this pull request Aug 12, 2026
## Summary
Several agentic workflows used HTML comments as machine-readable
markers. That does not work: gh-aw removes agent-provided HTML comments
when it sanitizes safe-output text. The comments were therefore not
present in the posted issue or PR content, so later workflow runs could
not reliably recognize earlier work. On #128405, this allowed
`ci-failure-fix` to post two different handoff comments.
This change replaces those comments with markers that survive
publishing:
- `safe-outputs.data` where the output type supports structured data.
- Stable visible Markdown fields where structured data is not supported
or would break the required content format.
Existing visible markers are still recognized so older workflow output
continues to work.
## Changes by workflow
- **`ci-failure-fix`**: Adds structured identifiers to fix PRs,
help-wanted PRs, and handoff comments. Deduplication now checks every
comment instead of assuming comments are at a fixed position, and it
still recognizes older visible markers.
- **`closed-issue-reference-check`**: Adds structured identifiers to
advisory comments. The pre-check skips issues that contain either the
new structured marker or the older workflow-specific marker and advisory
heading.
- **`ci-failure-scan`**: Moves KBE authoring guidance and the
verified-match count into collapsed, clearly labeled sections. KBE
bodies still contain exactly one JSON block, as required by Build
Analysis.
- **`ci-failure-scan-feedback`**: Reads the new `ci-failure-fix`
identifiers while keeping compatibility with older markers. Its tracker
identity and window are stored in a collapsed visible section, and
tracker updates explicitly replace the body instead of appending to it.
The shared workflow guidance now documents that HTML comments are
removed and explains when to use structured data or visible fields. The
affected generated workflows were refreshed with gh-aw v0.83.5.
## Related change
#131996 is the repository-wide mechanical refresh to gh-aw v0.83.5. This
PR contains the workflow behavior and authoring changes, and regenerates
the affected workflows with the same compiler version.
## Validation
- Compiled and validated the affected workflows with gh-aw v0.83.5.
- Ran poutine and zizmor on the changed workflows.
- Checked the KBE templates keep exactly one JSON block and contain the
required collapsed guidance and metadata.
> [!NOTE]
> This PR description was generated with GitHub Copilot.
---------
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skillsAgent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@vitek-karas@jkoritzinsky@PureWeen@kotlarmilos
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Refresh agentic workflows to gh-aw v0.83.5 by vitek-karas · Pull Request #131996 · dotnet/runtime · GitHub
Skip to content

Refresh agentic workflows to gh-aw v0.83.5 - #131996

Merged
vitek-karas merged 3 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-refresh-gh-aw-compiler
Aug 10, 2026
Merged

Refresh agentic workflows to gh-aw v0.83.5#131996
vitek-karas merged 3 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-refresh-gh-aw-compiler

Conversation

@vitek-karas

@vitek-karasvitek-karas commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

  • Upgrade all six agentic workflows from gh-aw v0.82.6 to the latest stable release, v0.85.4.
  • Regenerate the six workflow lock files and shared action pins with --schedule-seed dotnet/runtime.
  • Enable future workflows to use safe-output data payloads to store workflow-related metadata on issues and pull requests in a standard format.
  • Align the holistic-review trusted configuration paths with the engines supported by v0.85.4, removing the retired Crush, Antigravity, and OpenCode paths.
  • Accept v0.85.4's generated-surface updates: remove the unused agentics maintenance workflow because no workflow configures expiration, and remove the ineffective merge=ours lock-file attribute.

Validation

  • All six workflows compile successfully with gh-aw v0.85.4.
  • gh aw compile --schedule-seed dotnet/runtime --no-emit --validate --zizmor --poutine
  • A second full compilation produced an identical diff.

Note

This PR description was generated by GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI lite review requested due to automatic review settings August 7, 2026 13:05
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR refreshes the repository’s agentic GitHub Actions workflows to gh-aw v0.83.5, updating pinned action SHAs/container images and incorporating newer safe-outputs / MCP-gateway wiring. The changes primarily touch generated “*.lock.yml” workflows plus the generated agentic maintenance workflow and the shared gh-aw action pin map.

Changes:

  • Bump gh-aw compiler references across the lock workflows to v0.83.5 (and update associated action SHAs, firewall/MCP images, Copilot CLI version, etc.).
  • Update workflow runtime behavior around MCP gateway startup / docker socket group resolution, safe outputs processing, and additional error/guard outputs.
  • Regenerate the agentic maintenance workflow and update the gh-aw actions pin map.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
.github/workflows/holistic-review.lock.ymlUpdates pinned gh-aw/actions/containers and refactors MCP gateway + safe outputs plumbing for the holistic review workflow.
.github/workflows/closed-issue-reference-check.lock.ymlSame refresh for the closed-issue reference check workflow, including updated MCP server container/features and safe outputs processing.
.github/workflows/ci-failure-scan.lock.ymlSame refresh for the CI failure scan workflow, including updated pins and MCP gateway configuration.
.github/workflows/agentics-maintenance.ymlRegenerated maintenance workflow for v0.83.5; splits “close expired” operations into discussions/issues/PR jobs and updates action pins.
.github/aw/actions-lock.jsonUpdates the pinned github/gh-aw-actions/* entries to v0.83.5 SHAs.

Comment thread.github/workflows/holistic-review.lock.yml Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI review requested due to automatic review settings August 7, 2026 15:33

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated no new comments.

@PureWeenPureWeen left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we bump this to v0.85.4 instead? It was the latest stable release before this PR opened, while v0.83.5 is marked prerelease upstream.

It looks like v0.83.5 was selected because it introduced the safe-output metadata channel this PR needs, but I could not find a compatibility reason to stop there. Regenerating with v0.85.4 would also pick up the security hardening and fixes since then.

Note

This review comment was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI review requested due to automatic review settings August 9, 2026 15:03

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 10 out of 10 changed files in this pull request and generated 2 comments.

Suppressed comments (2)

.github/workflows/holistic-review.md:82

  • The PR title/description says the workflows are being refreshed to gh-aw v0.83.5, but this workflow source now states the recognized agent config paths are for gh-aw v0.85.4. The lock workflows in this PR also advertise they were generated with v0.85.4, so the PR metadata and the pinned compiler version appear out of sync.

Please reconcile by either updating the PR title/description to v0.85.4, or by pinning/regenerating the workflows with v0.83.5 so the version claims match across metadata, source .md, and .lock.yml files.

 # These are the agent configuration paths recognized by gh-aw v0.85.4.
# Re-audit this list whenever the pinned gh-aw compiler version changes.
trusted_agent_folders=(

.gitattributes:86

  • Removing merge=ours from the lock-workflow attribute will make Git merges try to merge the generated .github/workflows/*.lock.yml files normally, which can create frequent conflicts/churn for auto-generated content. If these files are intended to remain generator-owned, keep the merge strategy override to avoid noisy merges.
.github/workflows/*.lock.yml linguist-generated=true

Comment thread.github/workflows/closed-issue-reference-check.lock.yml
Comment thread.github/workflows/breaking-change-doc.lock.yml
@vitek-karas

Copy link
Copy Markdown
MemberAuthor

@PureWeen thanks for the feedback - I updated the PR to use the newest released version. Can you please take another look and possibly approve (need an approval for merge).

@vitek-karas
vitek-karas merged commit 1e4f4bc into dotnet:mainAug 10, 2026
143 of 145 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-refresh-gh-aw-compiler branch August 10, 2026 13:11
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 11, 2026
jtschuster pushed a commit to jtschuster/runtime that referenced this pull request Aug 11, 2026
## Summary
- Upgrade all six agentic workflows from gh-aw v0.82.6 to the latest
stable release, v0.85.4.
- Regenerate the six workflow lock files and shared action pins with
`--schedule-seed dotnet/runtime`.
- Enable future workflows to use safe-output `data` payloads to store
workflow-related metadata on issues and pull requests in a standard
format.
- Align the holistic-review trusted configuration paths with the engines
supported by v0.85.4, removing the retired Crush, Antigravity, and
OpenCode paths.
- Accept v0.85.4's generated-surface updates: remove the unused agentics
maintenance workflow because no workflow configures expiration, and
remove the ineffective `merge=ours` lock-file attribute.
## Validation
- All six workflows compile successfully with gh-aw v0.85.4.
- `gh aw compile --schedule-seed dotnet/runtime --no-emit --validate
--zizmor --poutine`
- A second full compilation produced an identical diff.
> [!NOTE]
> This PR description was generated by GitHub Copilot.
---------
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
vitek-karas added a commit that referenced this pull request Aug 12, 2026
## Summary
Several agentic workflows used HTML comments as machine-readable
markers. That does not work: gh-aw removes agent-provided HTML comments
when it sanitizes safe-output text. The comments were therefore not
present in the posted issue or PR content, so later workflow runs could
not reliably recognize earlier work. On #128405, this allowed
`ci-failure-fix` to post two different handoff comments.
This change replaces those comments with markers that survive
publishing:
- `safe-outputs.data` where the output type supports structured data.
- Stable visible Markdown fields where structured data is not supported
or would break the required content format.
Existing visible markers are still recognized so older workflow output
continues to work.
## Changes by workflow
- **`ci-failure-fix`**: Adds structured identifiers to fix PRs,
help-wanted PRs, and handoff comments. Deduplication now checks every
comment instead of assuming comments are at a fixed position, and it
still recognizes older visible markers.
- **`closed-issue-reference-check`**: Adds structured identifiers to
advisory comments. The pre-check skips issues that contain either the
new structured marker or the older workflow-specific marker and advisory
heading.
- **`ci-failure-scan`**: Moves KBE authoring guidance and the
verified-match count into collapsed, clearly labeled sections. KBE
bodies still contain exactly one JSON block, as required by Build
Analysis.
- **`ci-failure-scan-feedback`**: Reads the new `ci-failure-fix`
identifiers while keeping compatibility with older markers. Its tracker
identity and window are stored in a collapsed visible section, and
tracker updates explicitly replace the body instead of appending to it.
The shared workflow guidance now documents that HTML comments are
removed and explains when to use structured data or visible fields. The
affected generated workflows were refreshed with gh-aw v0.83.5.
## Related change
#131996 is the repository-wide mechanical refresh to gh-aw v0.83.5. This
PR contains the workflow behavior and authoring changes, and regenerates
the affected workflows with the same compiler version.
## Validation
- Compiled and validated the affected workflows with gh-aw v0.83.5.
- Ran poutine and zizmor on the changed workflows.
- Checked the KBE templates keep exactly one JSON block and contain the
required collapsed guidance and metadata.
> [!NOTE]
> This PR description was generated with GitHub Copilot.
---------
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skillsAgent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@vitek-karas@jkoritzinsky@PureWeen@kotlarmilos
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Refresh agentic workflows to gh-aw v0.83.5 by vitek-karas · Pull Request #131996 · dotnet/runtime · GitHub
Skip to content

Refresh agentic workflows to gh-aw v0.83.5 - #131996

Merged
vitek-karas merged 3 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-refresh-gh-aw-compiler
Aug 10, 2026
Merged

Refresh agentic workflows to gh-aw v0.83.5#131996
vitek-karas merged 3 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-refresh-gh-aw-compiler

Conversation

@vitek-karas

@vitek-karasvitek-karas commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

  • Upgrade all six agentic workflows from gh-aw v0.82.6 to the latest stable release, v0.85.4.
  • Regenerate the six workflow lock files and shared action pins with --schedule-seed dotnet/runtime.
  • Enable future workflows to use safe-output data payloads to store workflow-related metadata on issues and pull requests in a standard format.
  • Align the holistic-review trusted configuration paths with the engines supported by v0.85.4, removing the retired Crush, Antigravity, and OpenCode paths.
  • Accept v0.85.4's generated-surface updates: remove the unused agentics maintenance workflow because no workflow configures expiration, and remove the ineffective merge=ours lock-file attribute.

Validation

  • All six workflows compile successfully with gh-aw v0.85.4.
  • gh aw compile --schedule-seed dotnet/runtime --no-emit --validate --zizmor --poutine
  • A second full compilation produced an identical diff.

Note

This PR description was generated by GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI lite review requested due to automatic review settings August 7, 2026 13:05
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR refreshes the repository’s agentic GitHub Actions workflows to gh-aw v0.83.5, updating pinned action SHAs/container images and incorporating newer safe-outputs / MCP-gateway wiring. The changes primarily touch generated “*.lock.yml” workflows plus the generated agentic maintenance workflow and the shared gh-aw action pin map.

Changes:

  • Bump gh-aw compiler references across the lock workflows to v0.83.5 (and update associated action SHAs, firewall/MCP images, Copilot CLI version, etc.).
  • Update workflow runtime behavior around MCP gateway startup / docker socket group resolution, safe outputs processing, and additional error/guard outputs.
  • Regenerate the agentic maintenance workflow and update the gh-aw actions pin map.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
.github/workflows/holistic-review.lock.ymlUpdates pinned gh-aw/actions/containers and refactors MCP gateway + safe outputs plumbing for the holistic review workflow.
.github/workflows/closed-issue-reference-check.lock.ymlSame refresh for the closed-issue reference check workflow, including updated MCP server container/features and safe outputs processing.
.github/workflows/ci-failure-scan.lock.ymlSame refresh for the CI failure scan workflow, including updated pins and MCP gateway configuration.
.github/workflows/agentics-maintenance.ymlRegenerated maintenance workflow for v0.83.5; splits “close expired” operations into discussions/issues/PR jobs and updates action pins.
.github/aw/actions-lock.jsonUpdates the pinned github/gh-aw-actions/* entries to v0.83.5 SHAs.

Comment thread.github/workflows/holistic-review.lock.yml Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI review requested due to automatic review settings August 7, 2026 15:33

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated no new comments.

@PureWeenPureWeen left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we bump this to v0.85.4 instead? It was the latest stable release before this PR opened, while v0.83.5 is marked prerelease upstream.

It looks like v0.83.5 was selected because it introduced the safe-output metadata channel this PR needs, but I could not find a compatibility reason to stop there. Regenerating with v0.85.4 would also pick up the security hardening and fixes since then.

Note

This review comment was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI review requested due to automatic review settings August 9, 2026 15:03

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 10 out of 10 changed files in this pull request and generated 2 comments.

Suppressed comments (2)

.github/workflows/holistic-review.md:82

  • The PR title/description says the workflows are being refreshed to gh-aw v0.83.5, but this workflow source now states the recognized agent config paths are for gh-aw v0.85.4. The lock workflows in this PR also advertise they were generated with v0.85.4, so the PR metadata and the pinned compiler version appear out of sync.

Please reconcile by either updating the PR title/description to v0.85.4, or by pinning/regenerating the workflows with v0.83.5 so the version claims match across metadata, source .md, and .lock.yml files.

 # These are the agent configuration paths recognized by gh-aw v0.85.4.
# Re-audit this list whenever the pinned gh-aw compiler version changes.
trusted_agent_folders=(

.gitattributes:86

  • Removing merge=ours from the lock-workflow attribute will make Git merges try to merge the generated .github/workflows/*.lock.yml files normally, which can create frequent conflicts/churn for auto-generated content. If these files are intended to remain generator-owned, keep the merge strategy override to avoid noisy merges.
.github/workflows/*.lock.yml linguist-generated=true

Comment thread.github/workflows/closed-issue-reference-check.lock.yml
Comment thread.github/workflows/breaking-change-doc.lock.yml
@vitek-karas

Copy link
Copy Markdown
MemberAuthor

@PureWeen thanks for the feedback - I updated the PR to use the newest released version. Can you please take another look and possibly approve (need an approval for merge).

@vitek-karas
vitek-karas merged commit 1e4f4bc into dotnet:mainAug 10, 2026
143 of 145 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-refresh-gh-aw-compiler branch August 10, 2026 13:11
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 11, 2026
jtschuster pushed a commit to jtschuster/runtime that referenced this pull request Aug 11, 2026
## Summary
- Upgrade all six agentic workflows from gh-aw v0.82.6 to the latest
stable release, v0.85.4.
- Regenerate the six workflow lock files and shared action pins with
`--schedule-seed dotnet/runtime`.
- Enable future workflows to use safe-output `data` payloads to store
workflow-related metadata on issues and pull requests in a standard
format.
- Align the holistic-review trusted configuration paths with the engines
supported by v0.85.4, removing the retired Crush, Antigravity, and
OpenCode paths.
- Accept v0.85.4's generated-surface updates: remove the unused agentics
maintenance workflow because no workflow configures expiration, and
remove the ineffective `merge=ours` lock-file attribute.
## Validation
- All six workflows compile successfully with gh-aw v0.85.4.
- `gh aw compile --schedule-seed dotnet/runtime --no-emit --validate
--zizmor --poutine`
- A second full compilation produced an identical diff.
> [!NOTE]
> This PR description was generated by GitHub Copilot.
---------
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
vitek-karas added a commit that referenced this pull request Aug 12, 2026
## Summary
Several agentic workflows used HTML comments as machine-readable
markers. That does not work: gh-aw removes agent-provided HTML comments
when it sanitizes safe-output text. The comments were therefore not
present in the posted issue or PR content, so later workflow runs could
not reliably recognize earlier work. On #128405, this allowed
`ci-failure-fix` to post two different handoff comments.
This change replaces those comments with markers that survive
publishing:
- `safe-outputs.data` where the output type supports structured data.
- Stable visible Markdown fields where structured data is not supported
or would break the required content format.
Existing visible markers are still recognized so older workflow output
continues to work.
## Changes by workflow
- **`ci-failure-fix`**: Adds structured identifiers to fix PRs,
help-wanted PRs, and handoff comments. Deduplication now checks every
comment instead of assuming comments are at a fixed position, and it
still recognizes older visible markers.
- **`closed-issue-reference-check`**: Adds structured identifiers to
advisory comments. The pre-check skips issues that contain either the
new structured marker or the older workflow-specific marker and advisory
heading.
- **`ci-failure-scan`**: Moves KBE authoring guidance and the
verified-match count into collapsed, clearly labeled sections. KBE
bodies still contain exactly one JSON block, as required by Build
Analysis.
- **`ci-failure-scan-feedback`**: Reads the new `ci-failure-fix`
identifiers while keeping compatibility with older markers. Its tracker
identity and window are stored in a collapsed visible section, and
tracker updates explicitly replace the body instead of appending to it.
The shared workflow guidance now documents that HTML comments are
removed and explains when to use structured data or visible fields. The
affected generated workflows were refreshed with gh-aw v0.83.5.
## Related change
#131996 is the repository-wide mechanical refresh to gh-aw v0.83.5. This
PR contains the workflow behavior and authoring changes, and regenerates
the affected workflows with the same compiler version.
## Validation
- Compiled and validated the affected workflows with gh-aw v0.83.5.
- Ran poutine and zizmor on the changed workflows.
- Checked the KBE templates keep exactly one JSON block and contain the
required collapsed guidance and metadata.
> [!NOTE]
> This PR description was generated with GitHub Copilot.
---------
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skillsAgent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@vitek-karas@jkoritzinsky@PureWeen@kotlarmilos
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Refresh agentic workflows to gh-aw v0.83.5 by vitek-karas · Pull Request #131996 · dotnet/runtime · GitHub
Skip to content

Refresh agentic workflows to gh-aw v0.83.5 - #131996

Merged
vitek-karas merged 3 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-refresh-gh-aw-compiler
Aug 10, 2026
Merged

Refresh agentic workflows to gh-aw v0.83.5#131996
vitek-karas merged 3 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-refresh-gh-aw-compiler

Conversation

@vitek-karas

@vitek-karasvitek-karas commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

  • Upgrade all six agentic workflows from gh-aw v0.82.6 to the latest stable release, v0.85.4.
  • Regenerate the six workflow lock files and shared action pins with --schedule-seed dotnet/runtime.
  • Enable future workflows to use safe-output data payloads to store workflow-related metadata on issues and pull requests in a standard format.
  • Align the holistic-review trusted configuration paths with the engines supported by v0.85.4, removing the retired Crush, Antigravity, and OpenCode paths.
  • Accept v0.85.4's generated-surface updates: remove the unused agentics maintenance workflow because no workflow configures expiration, and remove the ineffective merge=ours lock-file attribute.

Validation

  • All six workflows compile successfully with gh-aw v0.85.4.
  • gh aw compile --schedule-seed dotnet/runtime --no-emit --validate --zizmor --poutine
  • A second full compilation produced an identical diff.

Note

This PR description was generated by GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI lite review requested due to automatic review settings August 7, 2026 13:05
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR refreshes the repository’s agentic GitHub Actions workflows to gh-aw v0.83.5, updating pinned action SHAs/container images and incorporating newer safe-outputs / MCP-gateway wiring. The changes primarily touch generated “*.lock.yml” workflows plus the generated agentic maintenance workflow and the shared gh-aw action pin map.

Changes:

  • Bump gh-aw compiler references across the lock workflows to v0.83.5 (and update associated action SHAs, firewall/MCP images, Copilot CLI version, etc.).
  • Update workflow runtime behavior around MCP gateway startup / docker socket group resolution, safe outputs processing, and additional error/guard outputs.
  • Regenerate the agentic maintenance workflow and update the gh-aw actions pin map.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
.github/workflows/holistic-review.lock.ymlUpdates pinned gh-aw/actions/containers and refactors MCP gateway + safe outputs plumbing for the holistic review workflow.
.github/workflows/closed-issue-reference-check.lock.ymlSame refresh for the closed-issue reference check workflow, including updated MCP server container/features and safe outputs processing.
.github/workflows/ci-failure-scan.lock.ymlSame refresh for the CI failure scan workflow, including updated pins and MCP gateway configuration.
.github/workflows/agentics-maintenance.ymlRegenerated maintenance workflow for v0.83.5; splits “close expired” operations into discussions/issues/PR jobs and updates action pins.
.github/aw/actions-lock.jsonUpdates the pinned github/gh-aw-actions/* entries to v0.83.5 SHAs.

Comment thread.github/workflows/holistic-review.lock.yml Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI review requested due to automatic review settings August 7, 2026 15:33

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated no new comments.

@PureWeenPureWeen left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we bump this to v0.85.4 instead? It was the latest stable release before this PR opened, while v0.83.5 is marked prerelease upstream.

It looks like v0.83.5 was selected because it introduced the safe-output metadata channel this PR needs, but I could not find a compatibility reason to stop there. Regenerating with v0.85.4 would also pick up the security hardening and fixes since then.

Note

This review comment was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI review requested due to automatic review settings August 9, 2026 15:03

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 10 out of 10 changed files in this pull request and generated 2 comments.

Suppressed comments (2)

.github/workflows/holistic-review.md:82

  • The PR title/description says the workflows are being refreshed to gh-aw v0.83.5, but this workflow source now states the recognized agent config paths are for gh-aw v0.85.4. The lock workflows in this PR also advertise they were generated with v0.85.4, so the PR metadata and the pinned compiler version appear out of sync.

Please reconcile by either updating the PR title/description to v0.85.4, or by pinning/regenerating the workflows with v0.83.5 so the version claims match across metadata, source .md, and .lock.yml files.

 # These are the agent configuration paths recognized by gh-aw v0.85.4.
# Re-audit this list whenever the pinned gh-aw compiler version changes.
trusted_agent_folders=(

.gitattributes:86

  • Removing merge=ours from the lock-workflow attribute will make Git merges try to merge the generated .github/workflows/*.lock.yml files normally, which can create frequent conflicts/churn for auto-generated content. If these files are intended to remain generator-owned, keep the merge strategy override to avoid noisy merges.
.github/workflows/*.lock.yml linguist-generated=true

Comment thread.github/workflows/closed-issue-reference-check.lock.yml
Comment thread.github/workflows/breaking-change-doc.lock.yml
@vitek-karas

Copy link
Copy Markdown
MemberAuthor

@PureWeen thanks for the feedback - I updated the PR to use the newest released version. Can you please take another look and possibly approve (need an approval for merge).

@vitek-karas
vitek-karas merged commit 1e4f4bc into dotnet:mainAug 10, 2026
143 of 145 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-refresh-gh-aw-compiler branch August 10, 2026 13:11
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 11, 2026
jtschuster pushed a commit to jtschuster/runtime that referenced this pull request Aug 11, 2026
## Summary
- Upgrade all six agentic workflows from gh-aw v0.82.6 to the latest
stable release, v0.85.4.
- Regenerate the six workflow lock files and shared action pins with
`--schedule-seed dotnet/runtime`.
- Enable future workflows to use safe-output `data` payloads to store
workflow-related metadata on issues and pull requests in a standard
format.
- Align the holistic-review trusted configuration paths with the engines
supported by v0.85.4, removing the retired Crush, Antigravity, and
OpenCode paths.
- Accept v0.85.4's generated-surface updates: remove the unused agentics
maintenance workflow because no workflow configures expiration, and
remove the ineffective `merge=ours` lock-file attribute.
## Validation
- All six workflows compile successfully with gh-aw v0.85.4.
- `gh aw compile --schedule-seed dotnet/runtime --no-emit --validate
--zizmor --poutine`
- A second full compilation produced an identical diff.
> [!NOTE]
> This PR description was generated by GitHub Copilot.
---------
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
vitek-karas added a commit that referenced this pull request Aug 12, 2026
## Summary
Several agentic workflows used HTML comments as machine-readable
markers. That does not work: gh-aw removes agent-provided HTML comments
when it sanitizes safe-output text. The comments were therefore not
present in the posted issue or PR content, so later workflow runs could
not reliably recognize earlier work. On #128405, this allowed
`ci-failure-fix` to post two different handoff comments.
This change replaces those comments with markers that survive
publishing:
- `safe-outputs.data` where the output type supports structured data.
- Stable visible Markdown fields where structured data is not supported
or would break the required content format.
Existing visible markers are still recognized so older workflow output
continues to work.
## Changes by workflow
- **`ci-failure-fix`**: Adds structured identifiers to fix PRs,
help-wanted PRs, and handoff comments. Deduplication now checks every
comment instead of assuming comments are at a fixed position, and it
still recognizes older visible markers.
- **`closed-issue-reference-check`**: Adds structured identifiers to
advisory comments. The pre-check skips issues that contain either the
new structured marker or the older workflow-specific marker and advisory
heading.
- **`ci-failure-scan`**: Moves KBE authoring guidance and the
verified-match count into collapsed, clearly labeled sections. KBE
bodies still contain exactly one JSON block, as required by Build
Analysis.
- **`ci-failure-scan-feedback`**: Reads the new `ci-failure-fix`
identifiers while keeping compatibility with older markers. Its tracker
identity and window are stored in a collapsed visible section, and
tracker updates explicitly replace the body instead of appending to it.
The shared workflow guidance now documents that HTML comments are
removed and explains when to use structured data or visible fields. The
affected generated workflows were refreshed with gh-aw v0.83.5.
## Related change
#131996 is the repository-wide mechanical refresh to gh-aw v0.83.5. This
PR contains the workflow behavior and authoring changes, and regenerates
the affected workflows with the same compiler version.
## Validation
- Compiled and validated the affected workflows with gh-aw v0.83.5.
- Ran poutine and zizmor on the changed workflows.
- Checked the KBE templates keep exactly one JSON block and contain the
required collapsed guidance and metadata.
> [!NOTE]
> This PR description was generated with GitHub Copilot.
---------
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skillsAgent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@vitek-karas@jkoritzinsky@PureWeen@kotlarmilos
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Refresh agentic workflows to gh-aw v0.83.5 by vitek-karas · Pull Request #131996 · dotnet/runtime · GitHub
Skip to content

Refresh agentic workflows to gh-aw v0.83.5 - #131996

Merged
vitek-karas merged 3 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-refresh-gh-aw-compiler
Aug 10, 2026
Merged

Refresh agentic workflows to gh-aw v0.83.5#131996
vitek-karas merged 3 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-refresh-gh-aw-compiler

Conversation

@vitek-karas

@vitek-karasvitek-karas commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

  • Upgrade all six agentic workflows from gh-aw v0.82.6 to the latest stable release, v0.85.4.
  • Regenerate the six workflow lock files and shared action pins with --schedule-seed dotnet/runtime.
  • Enable future workflows to use safe-output data payloads to store workflow-related metadata on issues and pull requests in a standard format.
  • Align the holistic-review trusted configuration paths with the engines supported by v0.85.4, removing the retired Crush, Antigravity, and OpenCode paths.
  • Accept v0.85.4's generated-surface updates: remove the unused agentics maintenance workflow because no workflow configures expiration, and remove the ineffective merge=ours lock-file attribute.

Validation

  • All six workflows compile successfully with gh-aw v0.85.4.
  • gh aw compile --schedule-seed dotnet/runtime --no-emit --validate --zizmor --poutine
  • A second full compilation produced an identical diff.

Note

This PR description was generated by GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI lite review requested due to automatic review settings August 7, 2026 13:05
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR refreshes the repository’s agentic GitHub Actions workflows to gh-aw v0.83.5, updating pinned action SHAs/container images and incorporating newer safe-outputs / MCP-gateway wiring. The changes primarily touch generated “*.lock.yml” workflows plus the generated agentic maintenance workflow and the shared gh-aw action pin map.

Changes:

  • Bump gh-aw compiler references across the lock workflows to v0.83.5 (and update associated action SHAs, firewall/MCP images, Copilot CLI version, etc.).
  • Update workflow runtime behavior around MCP gateway startup / docker socket group resolution, safe outputs processing, and additional error/guard outputs.
  • Regenerate the agentic maintenance workflow and update the gh-aw actions pin map.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
.github/workflows/holistic-review.lock.ymlUpdates pinned gh-aw/actions/containers and refactors MCP gateway + safe outputs plumbing for the holistic review workflow.
.github/workflows/closed-issue-reference-check.lock.ymlSame refresh for the closed-issue reference check workflow, including updated MCP server container/features and safe outputs processing.
.github/workflows/ci-failure-scan.lock.ymlSame refresh for the CI failure scan workflow, including updated pins and MCP gateway configuration.
.github/workflows/agentics-maintenance.ymlRegenerated maintenance workflow for v0.83.5; splits “close expired” operations into discussions/issues/PR jobs and updates action pins.
.github/aw/actions-lock.jsonUpdates the pinned github/gh-aw-actions/* entries to v0.83.5 SHAs.

Comment thread.github/workflows/holistic-review.lock.yml Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI review requested due to automatic review settings August 7, 2026 15:33

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated no new comments.

@PureWeenPureWeen left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we bump this to v0.85.4 instead? It was the latest stable release before this PR opened, while v0.83.5 is marked prerelease upstream.

It looks like v0.83.5 was selected because it introduced the safe-output metadata channel this PR needs, but I could not find a compatibility reason to stop there. Regenerating with v0.85.4 would also pick up the security hardening and fixes since then.

Note

This review comment was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI review requested due to automatic review settings August 9, 2026 15:03

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 10 out of 10 changed files in this pull request and generated 2 comments.

Suppressed comments (2)

.github/workflows/holistic-review.md:82

  • The PR title/description says the workflows are being refreshed to gh-aw v0.83.5, but this workflow source now states the recognized agent config paths are for gh-aw v0.85.4. The lock workflows in this PR also advertise they were generated with v0.85.4, so the PR metadata and the pinned compiler version appear out of sync.

Please reconcile by either updating the PR title/description to v0.85.4, or by pinning/regenerating the workflows with v0.83.5 so the version claims match across metadata, source .md, and .lock.yml files.

 # These are the agent configuration paths recognized by gh-aw v0.85.4.
# Re-audit this list whenever the pinned gh-aw compiler version changes.
trusted_agent_folders=(

.gitattributes:86

  • Removing merge=ours from the lock-workflow attribute will make Git merges try to merge the generated .github/workflows/*.lock.yml files normally, which can create frequent conflicts/churn for auto-generated content. If these files are intended to remain generator-owned, keep the merge strategy override to avoid noisy merges.
.github/workflows/*.lock.yml linguist-generated=true

Comment thread.github/workflows/closed-issue-reference-check.lock.yml
Comment thread.github/workflows/breaking-change-doc.lock.yml
@vitek-karas

Copy link
Copy Markdown
MemberAuthor

@PureWeen thanks for the feedback - I updated the PR to use the newest released version. Can you please take another look and possibly approve (need an approval for merge).

@vitek-karas
vitek-karas merged commit 1e4f4bc into dotnet:mainAug 10, 2026
143 of 145 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-refresh-gh-aw-compiler branch August 10, 2026 13:11
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 11, 2026
jtschuster pushed a commit to jtschuster/runtime that referenced this pull request Aug 11, 2026
## Summary
- Upgrade all six agentic workflows from gh-aw v0.82.6 to the latest
stable release, v0.85.4.
- Regenerate the six workflow lock files and shared action pins with
`--schedule-seed dotnet/runtime`.
- Enable future workflows to use safe-output `data` payloads to store
workflow-related metadata on issues and pull requests in a standard
format.
- Align the holistic-review trusted configuration paths with the engines
supported by v0.85.4, removing the retired Crush, Antigravity, and
OpenCode paths.
- Accept v0.85.4's generated-surface updates: remove the unused agentics
maintenance workflow because no workflow configures expiration, and
remove the ineffective `merge=ours` lock-file attribute.
## Validation
- All six workflows compile successfully with gh-aw v0.85.4.
- `gh aw compile --schedule-seed dotnet/runtime --no-emit --validate
--zizmor --poutine`
- A second full compilation produced an identical diff.
> [!NOTE]
> This PR description was generated by GitHub Copilot.
---------
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
vitek-karas added a commit that referenced this pull request Aug 12, 2026
## Summary
Several agentic workflows used HTML comments as machine-readable
markers. That does not work: gh-aw removes agent-provided HTML comments
when it sanitizes safe-output text. The comments were therefore not
present in the posted issue or PR content, so later workflow runs could
not reliably recognize earlier work. On #128405, this allowed
`ci-failure-fix` to post two different handoff comments.
This change replaces those comments with markers that survive
publishing:
- `safe-outputs.data` where the output type supports structured data.
- Stable visible Markdown fields where structured data is not supported
or would break the required content format.
Existing visible markers are still recognized so older workflow output
continues to work.
## Changes by workflow
- **`ci-failure-fix`**: Adds structured identifiers to fix PRs,
help-wanted PRs, and handoff comments. Deduplication now checks every
comment instead of assuming comments are at a fixed position, and it
still recognizes older visible markers.
- **`closed-issue-reference-check`**: Adds structured identifiers to
advisory comments. The pre-check skips issues that contain either the
new structured marker or the older workflow-specific marker and advisory
heading.
- **`ci-failure-scan`**: Moves KBE authoring guidance and the
verified-match count into collapsed, clearly labeled sections. KBE
bodies still contain exactly one JSON block, as required by Build
Analysis.
- **`ci-failure-scan-feedback`**: Reads the new `ci-failure-fix`
identifiers while keeping compatibility with older markers. Its tracker
identity and window are stored in a collapsed visible section, and
tracker updates explicitly replace the body instead of appending to it.
The shared workflow guidance now documents that HTML comments are
removed and explains when to use structured data or visible fields. The
affected generated workflows were refreshed with gh-aw v0.83.5.
## Related change
#131996 is the repository-wide mechanical refresh to gh-aw v0.83.5. This
PR contains the workflow behavior and authoring changes, and regenerates
the affected workflows with the same compiler version.
## Validation
- Compiled and validated the affected workflows with gh-aw v0.83.5.
- Ran poutine and zizmor on the changed workflows.
- Checked the KBE templates keep exactly one JSON block and contain the
required collapsed guidance and metadata.
> [!NOTE]
> This PR description was generated with GitHub Copilot.
---------
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skillsAgent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@vitek-karas@jkoritzinsky@PureWeen@kotlarmilos
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Refresh agentic workflows to gh-aw v0.83.5 by vitek-karas · Pull Request #131996 · dotnet/runtime · GitHub
Skip to content

Refresh agentic workflows to gh-aw v0.83.5 - #131996

Merged
vitek-karas merged 3 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-refresh-gh-aw-compiler
Aug 10, 2026
Merged

Refresh agentic workflows to gh-aw v0.83.5#131996
vitek-karas merged 3 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-refresh-gh-aw-compiler

Conversation

@vitek-karas

@vitek-karasvitek-karas commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

  • Upgrade all six agentic workflows from gh-aw v0.82.6 to the latest stable release, v0.85.4.
  • Regenerate the six workflow lock files and shared action pins with --schedule-seed dotnet/runtime.
  • Enable future workflows to use safe-output data payloads to store workflow-related metadata on issues and pull requests in a standard format.
  • Align the holistic-review trusted configuration paths with the engines supported by v0.85.4, removing the retired Crush, Antigravity, and OpenCode paths.
  • Accept v0.85.4's generated-surface updates: remove the unused agentics maintenance workflow because no workflow configures expiration, and remove the ineffective merge=ours lock-file attribute.

Validation

  • All six workflows compile successfully with gh-aw v0.85.4.
  • gh aw compile --schedule-seed dotnet/runtime --no-emit --validate --zizmor --poutine
  • A second full compilation produced an identical diff.

Note

This PR description was generated by GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI lite review requested due to automatic review settings August 7, 2026 13:05
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR refreshes the repository’s agentic GitHub Actions workflows to gh-aw v0.83.5, updating pinned action SHAs/container images and incorporating newer safe-outputs / MCP-gateway wiring. The changes primarily touch generated “*.lock.yml” workflows plus the generated agentic maintenance workflow and the shared gh-aw action pin map.

Changes:

  • Bump gh-aw compiler references across the lock workflows to v0.83.5 (and update associated action SHAs, firewall/MCP images, Copilot CLI version, etc.).
  • Update workflow runtime behavior around MCP gateway startup / docker socket group resolution, safe outputs processing, and additional error/guard outputs.
  • Regenerate the agentic maintenance workflow and update the gh-aw actions pin map.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
.github/workflows/holistic-review.lock.ymlUpdates pinned gh-aw/actions/containers and refactors MCP gateway + safe outputs plumbing for the holistic review workflow.
.github/workflows/closed-issue-reference-check.lock.ymlSame refresh for the closed-issue reference check workflow, including updated MCP server container/features and safe outputs processing.
.github/workflows/ci-failure-scan.lock.ymlSame refresh for the CI failure scan workflow, including updated pins and MCP gateway configuration.
.github/workflows/agentics-maintenance.ymlRegenerated maintenance workflow for v0.83.5; splits “close expired” operations into discussions/issues/PR jobs and updates action pins.
.github/aw/actions-lock.jsonUpdates the pinned github/gh-aw-actions/* entries to v0.83.5 SHAs.

Comment thread.github/workflows/holistic-review.lock.yml Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI review requested due to automatic review settings August 7, 2026 15:33

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated no new comments.

@PureWeenPureWeen left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we bump this to v0.85.4 instead? It was the latest stable release before this PR opened, while v0.83.5 is marked prerelease upstream.

It looks like v0.83.5 was selected because it introduced the safe-output metadata channel this PR needs, but I could not find a compatibility reason to stop there. Regenerating with v0.85.4 would also pick up the security hardening and fixes since then.

Note

This review comment was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI review requested due to automatic review settings August 9, 2026 15:03

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 10 out of 10 changed files in this pull request and generated 2 comments.

Suppressed comments (2)

.github/workflows/holistic-review.md:82

  • The PR title/description says the workflows are being refreshed to gh-aw v0.83.5, but this workflow source now states the recognized agent config paths are for gh-aw v0.85.4. The lock workflows in this PR also advertise they were generated with v0.85.4, so the PR metadata and the pinned compiler version appear out of sync.

Please reconcile by either updating the PR title/description to v0.85.4, or by pinning/regenerating the workflows with v0.83.5 so the version claims match across metadata, source .md, and .lock.yml files.

 # These are the agent configuration paths recognized by gh-aw v0.85.4.
# Re-audit this list whenever the pinned gh-aw compiler version changes.
trusted_agent_folders=(

.gitattributes:86

  • Removing merge=ours from the lock-workflow attribute will make Git merges try to merge the generated .github/workflows/*.lock.yml files normally, which can create frequent conflicts/churn for auto-generated content. If these files are intended to remain generator-owned, keep the merge strategy override to avoid noisy merges.
.github/workflows/*.lock.yml linguist-generated=true

Comment thread.github/workflows/closed-issue-reference-check.lock.yml
Comment thread.github/workflows/breaking-change-doc.lock.yml
@vitek-karas

Copy link
Copy Markdown
MemberAuthor

@PureWeen thanks for the feedback - I updated the PR to use the newest released version. Can you please take another look and possibly approve (need an approval for merge).

@vitek-karas
vitek-karas merged commit 1e4f4bc into dotnet:mainAug 10, 2026
143 of 145 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-refresh-gh-aw-compiler branch August 10, 2026 13:11
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 11, 2026
jtschuster pushed a commit to jtschuster/runtime that referenced this pull request Aug 11, 2026
## Summary
- Upgrade all six agentic workflows from gh-aw v0.82.6 to the latest
stable release, v0.85.4.
- Regenerate the six workflow lock files and shared action pins with
`--schedule-seed dotnet/runtime`.
- Enable future workflows to use safe-output `data` payloads to store
workflow-related metadata on issues and pull requests in a standard
format.
- Align the holistic-review trusted configuration paths with the engines
supported by v0.85.4, removing the retired Crush, Antigravity, and
OpenCode paths.
- Accept v0.85.4's generated-surface updates: remove the unused agentics
maintenance workflow because no workflow configures expiration, and
remove the ineffective `merge=ours` lock-file attribute.
## Validation
- All six workflows compile successfully with gh-aw v0.85.4.
- `gh aw compile --schedule-seed dotnet/runtime --no-emit --validate
--zizmor --poutine`
- A second full compilation produced an identical diff.
> [!NOTE]
> This PR description was generated by GitHub Copilot.
---------
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
vitek-karas added a commit that referenced this pull request Aug 12, 2026
## Summary
Several agentic workflows used HTML comments as machine-readable
markers. That does not work: gh-aw removes agent-provided HTML comments
when it sanitizes safe-output text. The comments were therefore not
present in the posted issue or PR content, so later workflow runs could
not reliably recognize earlier work. On #128405, this allowed
`ci-failure-fix` to post two different handoff comments.
This change replaces those comments with markers that survive
publishing:
- `safe-outputs.data` where the output type supports structured data.
- Stable visible Markdown fields where structured data is not supported
or would break the required content format.
Existing visible markers are still recognized so older workflow output
continues to work.
## Changes by workflow
- **`ci-failure-fix`**: Adds structured identifiers to fix PRs,
help-wanted PRs, and handoff comments. Deduplication now checks every
comment instead of assuming comments are at a fixed position, and it
still recognizes older visible markers.
- **`closed-issue-reference-check`**: Adds structured identifiers to
advisory comments. The pre-check skips issues that contain either the
new structured marker or the older workflow-specific marker and advisory
heading.
- **`ci-failure-scan`**: Moves KBE authoring guidance and the
verified-match count into collapsed, clearly labeled sections. KBE
bodies still contain exactly one JSON block, as required by Build
Analysis.
- **`ci-failure-scan-feedback`**: Reads the new `ci-failure-fix`
identifiers while keeping compatibility with older markers. Its tracker
identity and window are stored in a collapsed visible section, and
tracker updates explicitly replace the body instead of appending to it.
The shared workflow guidance now documents that HTML comments are
removed and explains when to use structured data or visible fields. The
affected generated workflows were refreshed with gh-aw v0.83.5.
## Related change
#131996 is the repository-wide mechanical refresh to gh-aw v0.83.5. This
PR contains the workflow behavior and authoring changes, and regenerates
the affected workflows with the same compiler version.
## Validation
- Compiled and validated the affected workflows with gh-aw v0.83.5.
- Ran poutine and zizmor on the changed workflows.
- Checked the KBE templates keep exactly one JSON block and contain the
required collapsed guidance and metadata.
> [!NOTE]
> This PR description was generated with GitHub Copilot.
---------
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skillsAgent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@vitek-karas@jkoritzinsky@PureWeen@kotlarmilos
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Refresh agentic workflows to gh-aw v0.83.5 by vitek-karas · Pull Request #131996 · dotnet/runtime · GitHub
Skip to content

Refresh agentic workflows to gh-aw v0.83.5 - #131996

Merged
vitek-karas merged 3 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-refresh-gh-aw-compiler
Aug 10, 2026
Merged

Refresh agentic workflows to gh-aw v0.83.5#131996
vitek-karas merged 3 commits into
dotnet:mainfrom
vitek-karas:vitek-karas-refresh-gh-aw-compiler

Conversation

@vitek-karas

@vitek-karasvitek-karas commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

  • Upgrade all six agentic workflows from gh-aw v0.82.6 to the latest stable release, v0.85.4.
  • Regenerate the six workflow lock files and shared action pins with --schedule-seed dotnet/runtime.
  • Enable future workflows to use safe-output data payloads to store workflow-related metadata on issues and pull requests in a standard format.
  • Align the holistic-review trusted configuration paths with the engines supported by v0.85.4, removing the retired Crush, Antigravity, and OpenCode paths.
  • Accept v0.85.4's generated-surface updates: remove the unused agentics maintenance workflow because no workflow configures expiration, and remove the ineffective merge=ours lock-file attribute.

Validation

  • All six workflows compile successfully with gh-aw v0.85.4.
  • gh aw compile --schedule-seed dotnet/runtime --no-emit --validate --zizmor --poutine
  • A second full compilation produced an identical diff.

Note

This PR description was generated by GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI lite review requested due to automatic review settings August 7, 2026 13:05
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
15 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR refreshes the repository’s agentic GitHub Actions workflows to gh-aw v0.83.5, updating pinned action SHAs/container images and incorporating newer safe-outputs / MCP-gateway wiring. The changes primarily touch generated “*.lock.yml” workflows plus the generated agentic maintenance workflow and the shared gh-aw action pin map.

Changes:

  • Bump gh-aw compiler references across the lock workflows to v0.83.5 (and update associated action SHAs, firewall/MCP images, Copilot CLI version, etc.).
  • Update workflow runtime behavior around MCP gateway startup / docker socket group resolution, safe outputs processing, and additional error/guard outputs.
  • Regenerate the agentic maintenance workflow and update the gh-aw actions pin map.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
.github/workflows/holistic-review.lock.ymlUpdates pinned gh-aw/actions/containers and refactors MCP gateway + safe outputs plumbing for the holistic review workflow.
.github/workflows/closed-issue-reference-check.lock.ymlSame refresh for the closed-issue reference check workflow, including updated MCP server container/features and safe outputs processing.
.github/workflows/ci-failure-scan.lock.ymlSame refresh for the CI failure scan workflow, including updated pins and MCP gateway configuration.
.github/workflows/agentics-maintenance.ymlRegenerated maintenance workflow for v0.83.5; splits “close expired” operations into discussions/issues/PR jobs and updates action pins.
.github/aw/actions-lock.jsonUpdates the pinned github/gh-aw-actions/* entries to v0.83.5 SHAs.

Comment thread.github/workflows/holistic-review.lock.yml Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI review requested due to automatic review settings August 7, 2026 15:33

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated no new comments.

@PureWeenPureWeen left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we bump this to v0.85.4 instead? It was the latest stable release before this PR opened, while v0.83.5 is marked prerelease upstream.

It looks like v0.83.5 was selected because it introduced the safe-output metadata channel this PR needs, but I could not find a compatibility reason to stop there. Regenerating with v0.85.4 would also pick up the security hardening and fixes since then.

Note

This review comment was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
CopilotAI review requested due to automatic review settings August 9, 2026 15:03

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 10 out of 10 changed files in this pull request and generated 2 comments.

Suppressed comments (2)

.github/workflows/holistic-review.md:82

  • The PR title/description says the workflows are being refreshed to gh-aw v0.83.5, but this workflow source now states the recognized agent config paths are for gh-aw v0.85.4. The lock workflows in this PR also advertise they were generated with v0.85.4, so the PR metadata and the pinned compiler version appear out of sync.

Please reconcile by either updating the PR title/description to v0.85.4, or by pinning/regenerating the workflows with v0.83.5 so the version claims match across metadata, source .md, and .lock.yml files.

 # These are the agent configuration paths recognized by gh-aw v0.85.4.
# Re-audit this list whenever the pinned gh-aw compiler version changes.
trusted_agent_folders=(

.gitattributes:86

  • Removing merge=ours from the lock-workflow attribute will make Git merges try to merge the generated .github/workflows/*.lock.yml files normally, which can create frequent conflicts/churn for auto-generated content. If these files are intended to remain generator-owned, keep the merge strategy override to avoid noisy merges.
.github/workflows/*.lock.yml linguist-generated=true

Comment thread.github/workflows/closed-issue-reference-check.lock.yml
Comment thread.github/workflows/breaking-change-doc.lock.yml
@vitek-karas

Copy link
Copy Markdown
MemberAuthor

@PureWeen thanks for the feedback - I updated the PR to use the newest released version. Can you please take another look and possibly approve (need an approval for merge).

@vitek-karas
vitek-karas merged commit 1e4f4bc into dotnet:mainAug 10, 2026
143 of 145 checks passed
@vitek-karas
vitek-karas deleted the vitek-karas-refresh-gh-aw-compiler branch August 10, 2026 13:11
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 11, 2026
jtschuster pushed a commit to jtschuster/runtime that referenced this pull request Aug 11, 2026
## Summary
- Upgrade all six agentic workflows from gh-aw v0.82.6 to the latest
stable release, v0.85.4.
- Regenerate the six workflow lock files and shared action pins with
`--schedule-seed dotnet/runtime`.
- Enable future workflows to use safe-output `data` payloads to store
workflow-related metadata on issues and pull requests in a standard
format.
- Align the holistic-review trusted configuration paths with the engines
supported by v0.85.4, removing the retired Crush, Antigravity, and
OpenCode paths.
- Accept v0.85.4's generated-surface updates: remove the unused agentics
maintenance workflow because no workflow configures expiration, and
remove the ineffective `merge=ours` lock-file attribute.
## Validation
- All six workflows compile successfully with gh-aw v0.85.4.
- `gh aw compile --schedule-seed dotnet/runtime --no-emit --validate
--zizmor --poutine`
- A second full compilation produced an identical diff.
> [!NOTE]
> This PR description was generated by GitHub Copilot.
---------
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a51b11ef-6d6e-4c79-b324-5fc9c08a8e18
vitek-karas added a commit that referenced this pull request Aug 12, 2026
## Summary
Several agentic workflows used HTML comments as machine-readable
markers. That does not work: gh-aw removes agent-provided HTML comments
when it sanitizes safe-output text. The comments were therefore not
present in the posted issue or PR content, so later workflow runs could
not reliably recognize earlier work. On #128405, this allowed
`ci-failure-fix` to post two different handoff comments.
This change replaces those comments with markers that survive
publishing:
- `safe-outputs.data` where the output type supports structured data.
- Stable visible Markdown fields where structured data is not supported
or would break the required content format.
Existing visible markers are still recognized so older workflow output
continues to work.
## Changes by workflow
- **`ci-failure-fix`**: Adds structured identifiers to fix PRs,
help-wanted PRs, and handoff comments. Deduplication now checks every
comment instead of assuming comments are at a fixed position, and it
still recognizes older visible markers.
- **`closed-issue-reference-check`**: Adds structured identifiers to
advisory comments. The pre-check skips issues that contain either the
new structured marker or the older workflow-specific marker and advisory
heading.
- **`ci-failure-scan`**: Moves KBE authoring guidance and the
verified-match count into collapsed, clearly labeled sections. KBE
bodies still contain exactly one JSON block, as required by Build
Analysis.
- **`ci-failure-scan-feedback`**: Reads the new `ci-failure-fix`
identifiers while keeping compatibility with older markers. Its tracker
identity and window are stored in a collapsed visible section, and
tracker updates explicitly replace the body instead of appending to it.
The shared workflow guidance now documents that HTML comments are
removed and explains when to use structured data or visible fields. The
affected generated workflows were refreshed with gh-aw v0.83.5.
## Related change
#131996 is the repository-wide mechanical refresh to gh-aw v0.83.5. This
PR contains the workflow behavior and authoring changes, and regenerates
the affected workflows with the same compiler version.
## Validation
- Compiled and validated the affected workflows with gh-aw v0.83.5.
- Ran poutine and zizmor on the changed workflows.
- Checked the KBE templates keep exactly one JSON block and contain the
required collapsed guidance and metadata.
> [!NOTE]
> This PR description was generated with GitHub Copilot.
---------
Copilot-Session: 2038caaa-4cae-49b0-84e0-a077f5c91aa0
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-skillsAgent Skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@vitek-karas@jkoritzinsky@PureWeen@kotlarmilos