Skip to content

Bump mcpg (DIFC proxy) to v0.3.8 - #32128

Merged
pelikhan merged 7 commits into
mainfrom
copilot/bump-mcpg-to-v038
May 14, 2026
Merged

Bump mcpg (DIFC proxy) to v0.3.8#32128
pelikhan merged 7 commits into
mainfrom
copilot/bump-mcpg-to-v038

Conversation

CopilotAI commented May 14, 2026

Copy link
Copy Markdown
Contributor

Bumps the MCP Gateway (gh-aw-mcpg) container image from v0.3.6 to v0.3.8, picking up the dead_code compiler fix for ORDER_HIGH_TO_LOW.

Changes

  • pkg/constants/version_constants.go: DefaultMCPGatewayVersionv0.3.6v0.3.8
  • 227 .lock.yml files: Regenerated via double make recompile to update container image tags and refresh pinned SHA digests

Changeset

  • Type: patch
  • Description: Bump the MCP gateway image to v0.3.8 so compiled workflows use the updated gh-aw-mcpg container.

Generated by Changeset Generator for issue #32128 ·

CopilotAI linked an issue May 14, 2026 that may be closed by this pull request
CopilotAIand others added 2 commits May 14, 2026 13:45
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
CopilotAI changed the title [WIP] Bump mcpg version to v0.3.8Bump mcpg (DIFC proxy) to v0.3.8May 14, 2026
CopilotAI requested a review from lpcoxMay 14, 2026 13:48
@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot resolve container sha and recompile

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

CopilotAI commented May 14, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot resolve container sha and recompile

Done. Resolved ghcr.io/github/gh-aw-mcpg:v0.3.8sha256:71e102af76e1ce10b455d2a2ef5717d9cc4c135a5db06fbadcb58e6c1a950cd4, added the pin to actions-lock.json, and recompiled all 227 lock files to embed the pinned digest. Committed in da7bbfc.

CopilotAI requested a review from pelikhanMay 14, 2026 13:58
@pelikhan
pelikhan marked this pull request as ready for review May 14, 2026 14:02
CopilotAI review requested due to automatic review settings May 14, 2026 14:02
@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot merge main and recompile

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Bumps the default MCP Gateway container from v0.3.6 to v0.3.8 and regenerates workflow lockfiles to use the new pinned image digest.

Changes:

  • Updates DefaultMCPGatewayVersion to v0.3.8.
  • Refreshes lockfile manifests, image predownload commands, and MCP gateway runtime image tags/digests.
Show a summary per file
FileDescription
pkg/constants/version_constants.goUpdates the default MCP Gateway version.
.github/workflows/*.lock.ymlRegenerated workflow lockfiles to reference gh-aw-mcpg:v0.3.8 with the refreshed SHA digest.

Copilot's findings

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 102/231 changed files
  • Comments generated: 0

CopilotAIand others added 2 commits May 14, 2026 14:08
…v038
# Conflicts:
#	.github/workflows/ab-testing-advisor.lock.yml
#	.github/workflows/ace-editor.lock.yml
#	.github/workflows/agent-performance-analyzer.lock.yml
#	.github/workflows/agent-persona-explorer.lock.yml
#	.github/workflows/ai-moderator.lock.yml
#	.github/workflows/api-consumption-report.lock.yml
#	.github/workflows/approach-validator.lock.yml
#	.github/workflows/archie.lock.yml
#	.github/workflows/architecture-guardian.lock.yml
#	.github/workflows/artifacts-summary.lock.yml
#	.github/workflows/audit-workflows.lock.yml
#	.github/workflows/auto-triage-issues.lock.yml
#	.github/workflows/aw-failure-investigator.lock.yml
#	.github/workflows/aw-portfolio-yield.lock.yml
#	.github/workflows/blog-auditor.lock.yml
#	.github/workflows/bot-detection.lock.yml
#	.github/workflows/brave.lock.yml
#	.github/workflows/breaking-change-checker.lock.yml
#	.github/workflows/changeset.lock.yml
#	.github/workflows/ci-coach.lock.yml
#	.github/workflows/ci-doctor.lock.yml
#	.github/workflows/claude-code-user-docs-review.lock.yml
#	.github/workflows/cli-consistency-checker.lock.yml
#	.github/workflows/cli-version-checker.lock.yml
#	.github/workflows/cloclo.lock.yml
#	.github/workflows/code-scanning-fixer.lock.yml
#	.github/workflows/code-simplifier.lock.yml
#	.github/workflows/codex-github-remote-mcp-test.lock.yml
#	.github/workflows/commit-changes-analyzer.lock.yml
#	.github/workflows/constraint-solving-potd.lock.yml
#	.github/workflows/contribution-check.lock.yml
#	.github/workflows/copilot-agent-analysis.lock.yml
#	.github/workflows/copilot-cli-deep-research.lock.yml
#	.github/workflows/copilot-opt.lock.yml
#	.github/workflows/copilot-pr-merged-report.lock.yml
#	.github/workflows/copilot-pr-nlp-analysis.lock.yml
#	.github/workflows/copilot-pr-prompt-analysis.lock.yml
#	.github/workflows/copilot-session-insights.lock.yml
#	.github/workflows/copilot-token-audit.lock.yml
#	.github/workflows/copilot-token-optimizer.lock.yml
#	.github/workflows/craft.lock.yml
#	.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml
#	.github/workflows/daily-agentrx-trace-optimizer.lock.yml
#	.github/workflows/daily-architecture-diagram.lock.yml
#	.github/workflows/daily-assign-issue-to-user.lock.yml
#	.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml
#	.github/workflows/daily-aw-cross-repo-compile-check.lock.yml
#	.github/workflows/daily-cache-strategy-analyzer.lock.yml
#	.github/workflows/daily-caveman-optimizer.lock.yml
#	.github/workflows/daily-choice-test.lock.yml
#	.github/workflows/daily-cli-performance.lock.yml
#	.github/workflows/daily-cli-tools-tester.lock.yml
#	.github/workflows/daily-code-metrics.lock.yml
#	.github/workflows/daily-community-attribution.lock.yml
#	.github/workflows/daily-compiler-quality.lock.yml
#	.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml
#	.github/workflows/daily-doc-healer.lock.yml
#	.github/workflows/daily-doc-updater.lock.yml
#	.github/workflows/daily-experiment-report.lock.yml
#	.github/workflows/daily-fact.lock.yml
#	.github/workflows/daily-file-diet.lock.yml
#	.github/workflows/daily-firewall-report.lock.yml
#	.github/workflows/daily-function-namer.lock.yml
#	.github/workflows/daily-geo-optimizer.lock.yml
#	.github/workflows/daily-grafana-otel-instrumentation-advisor.lock.yml
#	.github/workflows/daily-hippo-learn.lock.yml
#	.github/workflows/daily-issues-report.lock.yml
#	.github/workflows/daily-malicious-code-scan.lock.yml
#	.github/workflows/daily-mcp-concurrency-analysis.lock.yml
#	.github/workflows/daily-model-inventory.lock.yml
#	.github/workflows/daily-multi-device-docs-tester.lock.yml
#	.github/workflows/daily-news.lock.yml
#	.github/workflows/daily-observability-report.lock.yml
#	.github/workflows/daily-otel-instrumentation-advisor.lock.yml
#	.github/workflows/daily-performance-summary.lock.yml
#	.github/workflows/daily-regulatory.lock.yml
#	.github/workflows/daily-rendering-scripts-verifier.lock.yml
#	.github/workflows/daily-repo-chronicle.lock.yml
#	.github/workflows/daily-safe-output-integrator.lock.yml
#	.github/workflows/daily-safe-output-optimizer.lock.yml
#	.github/workflows/daily-safe-outputs-conformance.lock.yml
#	.github/workflows/daily-secrets-analysis.lock.yml
#	.github/workflows/daily-security-observability.lock.yml
#	.github/workflows/daily-security-red-team.lock.yml
#	.github/workflows/daily-semgrep-scan.lock.yml
#	.github/workflows/daily-sentrux-report.lock.yml
#	.github/workflows/daily-skill-optimizer.lock.yml
#	.github/workflows/daily-spdd-spec-planner.lock.yml
#	.github/workflows/daily-subagent-optimizer.lock.yml
#	.github/workflows/daily-syntax-error-quality.lock.yml
#	.github/workflows/daily-team-evolution-insights.lock.yml
#	.github/workflows/daily-team-status.lock.yml
#	.github/workflows/daily-testify-uber-super-expert.lock.yml
#	.github/workflows/daily-token-consumption-report.lock.yml
#	.github/workflows/daily-workflow-updater.lock.yml
#	.github/workflows/dead-code-remover.lock.yml
#	.github/workflows/deep-report.lock.yml
#	.github/workflows/delight.lock.yml
#	.github/workflows/dependabot-burner.lock.yml
#	.github/workflows/dependabot-campaign.lock.yml
#	.github/workflows/dependabot-go-checker.lock.yml
#	.github/workflows/dependabot-repair.lock.yml
#	.github/workflows/dependabot-worker.lock.yml
#	.github/workflows/deployment-incident-monitor.lock.yml
#	.github/workflows/design-decision-gate.lock.yml
#	.github/workflows/dev-hawk.lock.yml
#	.github/workflows/dev.lock.yml
#	.github/workflows/developer-docs-consolidator.lock.yml
#	.github/workflows/dictation-prompt.lock.yml
#	.github/workflows/discussion-task-miner.lock.yml
#	.github/workflows/docs-noob-tester.lock.yml
#	.github/workflows/draft-pr-cleanup.lock.yml
#	.github/workflows/duplicate-code-detector.lock.yml
#	.github/workflows/example-permissions-warning.lock.yml
#	.github/workflows/example-workflow-analyzer.lock.yml
#	.github/workflows/firewall-escape.lock.yml
#	.github/workflows/firewall.lock.yml
#	.github/workflows/functional-pragmatist.lock.yml
#	.github/workflows/github-mcp-structural-analysis.lock.yml
#	.github/workflows/github-mcp-tools-report.lock.yml
#	.github/workflows/github-remote-mcp-auth-test.lock.yml
#	.github/workflows/glossary-maintainer.lock.yml
#	.github/workflows/go-fan.lock.yml
#	.github/workflows/go-logger.lock.yml
#	.github/workflows/go-pattern-detector.lock.yml
#	.github/workflows/gpclean.lock.yml
#	.github/workflows/grumpy-reviewer.lock.yml
#	.github/workflows/hippo-embed.lock.yml
#	.github/workflows/hourly-ci-cleaner.lock.yml
#	.github/workflows/instructions-janitor.lock.yml
#	.github/workflows/issue-arborist.lock.yml
#	.github/workflows/issue-monster.lock.yml
#	.github/workflows/issue-triage-agent.lock.yml
#	.github/workflows/jsweep.lock.yml
#	.github/workflows/layout-spec-maintainer.lock.yml
#	.github/workflows/lockfile-stats.lock.yml
#	.github/workflows/mattpocock-skills-reviewer.lock.yml
#	.github/workflows/mcp-inspector.lock.yml
#	.github/workflows/mergefest.lock.yml
#	.github/workflows/metrics-collector.lock.yml
#	.github/workflows/necromancer.lock.yml
#	.github/workflows/notion-issue-summary.lock.yml
#	.github/workflows/org-health-report.lock.yml
#	.github/workflows/outcome-collector.lock.yml
#	.github/workflows/pdf-summary.lock.yml
#	.github/workflows/plan.lock.yml
#	.github/workflows/poem-bot.lock.yml
#	.github/workflows/pr-code-quality-reviewer.lock.yml
#	.github/workflows/pr-nitpick-reviewer.lock.yml
#	.github/workflows/pr-sous-chef.lock.yml
#	.github/workflows/pr-triage-agent.lock.yml
#	.github/workflows/prompt-clustering-analysis.lock.yml
#	.github/workflows/python-data-charts.lock.yml
#	.github/workflows/q.lock.yml
#	.github/workflows/refactoring-cadence.lock.yml
#	.github/workflows/refiner.lock.yml
#	.github/workflows/release.lock.yml
#	.github/workflows/repo-audit-analyzer.lock.yml
#	.github/workflows/repo-tree-map.lock.yml
#	.github/workflows/repository-quality-improver.lock.yml
#	.github/workflows/research.lock.yml
#	.github/workflows/safe-output-health.lock.yml
#	.github/workflows/schema-consistency-checker.lock.yml
#	.github/workflows/schema-feature-coverage.lock.yml
#	.github/workflows/scout.lock.yml
#	.github/workflows/security-compliance.lock.yml
#	.github/workflows/security-review.lock.yml
#	.github/workflows/semantic-function-refactor.lock.yml
#	.github/workflows/sergo.lock.yml
#	.github/workflows/slide-deck-maintainer.lock.yml
#	.github/workflows/smoke-agent-all-merged.lock.yml
#	.github/workflows/smoke-agent-all-none.lock.yml
#	.github/workflows/smoke-agent-public-approved.lock.yml
#	.github/workflows/smoke-agent-public-none.lock.yml
#	.github/workflows/smoke-agent-scoped-approved.lock.yml
#	.github/workflows/smoke-call-workflow.lock.yml
#	.github/workflows/smoke-ci.lock.yml
#	.github/workflows/smoke-claude.lock.yml
#	.github/workflows/smoke-codex.lock.yml
#	.github/workflows/smoke-copilot-arm.lock.yml
#	.github/workflows/smoke-copilot.lock.yml
#	.github/workflows/smoke-create-cross-repo-pr.lock.yml
#	.github/workflows/smoke-crush.lock.yml
#	.github/workflows/smoke-gemini.lock.yml
#	.github/workflows/smoke-multi-pr.lock.yml
#	.github/workflows/smoke-opencode.lock.yml
#	.github/workflows/smoke-otel-backends.lock.yml
#	.github/workflows/smoke-otel.lock.yml
#	.github/workflows/smoke-pi.lock.yml
#	.github/workflows/smoke-project.lock.yml
#	.github/workflows/smoke-service-ports.lock.yml
#	.github/workflows/smoke-temporary-id.lock.yml
#	.github/workflows/smoke-test-tools.lock.yml
#	.github/workflows/smoke-update-cross-repo-pr.lock.yml
#	.github/workflows/smoke-workflow-call-with-inputs.lock.yml
#	.github/workflows/smoke-workflow-call.lock.yml
#	.github/workflows/spec-enforcer.lock.yml
#	.github/workflows/spec-extractor.lock.yml
#	.github/workflows/spec-librarian.lock.yml
#	.github/workflows/stale-pr-cleanup.lock.yml
#	.github/workflows/stale-repo-identifier.lock.yml
#	.github/workflows/static-analysis-report.lock.yml
#	.github/workflows/step-name-alignment.lock.yml
#	.github/workflows/sub-issue-closer.lock.yml
#	.github/workflows/super-linter.lock.yml
#	.github/workflows/technical-doc-writer.lock.yml
#	.github/workflows/terminal-stylist.lock.yml
#	.github/workflows/test-create-pr-error-handling.lock.yml
#	.github/workflows/test-dispatcher.lock.yml
#	.github/workflows/test-project-url-default.lock.yml
#	.github/workflows/test-quality-sentinel.lock.yml
#	.github/workflows/test-workflow.lock.yml
#	.github/workflows/tidy.lock.yml
#	.github/workflows/typist.lock.yml
#	.github/workflows/ubuntu-image-analyzer.lock.yml
#	.github/workflows/unbloat-docs.lock.yml
#	.github/workflows/update-astro.lock.yml
#	.github/workflows/video-analyzer.lock.yml
#	.github/workflows/visual-regression-checker.lock.yml
#	.github/workflows/weekly-blog-post-writer.lock.yml
#	.github/workflows/weekly-editors-health-check.lock.yml
#	.github/workflows/weekly-issue-summary.lock.yml
#	.github/workflows/weekly-safe-outputs-spec-review.lock.yml
#	.github/workflows/workflow-generator.lock.yml
#	.github/workflows/workflow-health-manager.lock.yml
#	.github/workflows/workflow-normalizer.lock.yml
#	.github/workflows/workflow-skill-extractor.lock.yml
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

CopilotAI commented May 14, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot merge main and recompile

Done. Merged main (AWF firewall v0.25.46) and recompiled all 227 lock files — they now carry both gh-aw-firewall:0.25.46 and gh-aw-mcpg:v0.3.8@sha256:71e102af76e1ce10b455d2a2ef5717d9cc4c135a5db06fbadcb58e6c1a950cd4.

@github-actions

github-actionsBot commented May 14, 2026

Copy link
Copy Markdown
Contributor

Smoke OTEL — OTEL telemetry verified

@github-actions

github-actionsBot commented May 14, 2026

Copy link
Copy Markdown
Contributor

⚠️ Security scanning failed for Smoke OTEL Backends. Review the logs for details.

@github-actions

github-actionsBot commented May 14, 2026

Copy link
Copy Markdown
Contributor

⚠️ Security scanning failed for Smoke Claude. Review the logs for details.

@github-actions

github-actionsBot commented May 14, 2026

Copy link
Copy Markdown
Contributor

⚠️ Security scanning failed for Smoke Gemini. Review the logs for details.

@github-actions

Copy link
Copy Markdown
Contributor

📰 BREAKING: Smoke Copilot is now investigating this pull request. Sources say the story is developing...

@github-actions

github-actionsBot commented May 14, 2026

Copy link
Copy Markdown
Contributor

🚀 Smoke PiMISSION COMPLETE! Pi delivered. 🥧

@github-actions

github-actionsBot commented May 14, 2026

Copy link
Copy Markdown
Contributor

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

@github-actions

Copy link
Copy Markdown
Contributor

Commit pushed: 17c4b5c

Generated by Changeset Generator

@github-actions

Copy link
Copy Markdown
Contributor

Agent Container Tool Check

ToolStatusVersion
bash5.2.21
shavailable
git2.53.0
jq1.7
yq4.52.5
curl8.5.0
gh2.89.0
node22.22.2
python33.10.16 (PyPy 7.3.19)
go1.24.13
java10.0.201
dotnetnot found

Result: 11/12 tools available ⚠️FAILdotnet is missing

🔧 Tool validation by Agent Container Smoke Test · ● 1.2M ·

@pelikhan
pelikhan merged commit 6553ba7 into mainMay 14, 2026
@pelikhan
pelikhan deleted the copilot/bump-mcpg-to-v038 branch May 14, 2026 14:25
@github-actions

Copy link
Copy Markdown
Contributor

PRs: #32136 Add missing pkg/linters package spec and complete pkg/cli dependency list; #32114 fix: insert -- end-of-options separator before prompt to prevent ENAMETOOLONG
Tests 1-5: ✅ GitHub MCP, ✅ Serena, ✅ Playwright, ❌ Web Fetch MCP, ✅ file write
Tests 6-10: ✅ bash verify, ✅ build, ✅ comment memory, ✅ cache memory, ✅ issue field
Overall status: FAIL

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex ·

@github-actions

Copy link
Copy Markdown
Contributor

Comment Memory

Steel sky after tests
Quiet logs hold passing light
Dawn signs the build green

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex ·

@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Security scanning failed for Smoke Copilot. Review the logs for details.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bump mcpg to v0.3.8

4 participants

@pelikhan@lpcox