Skip to content

Bump AWF to v0.27.27 and MCPG to v0.4.0 - #44173

Merged
pelikhan merged 6 commits into
mainfrom
copilot/bump-mcpg-to-v040-firewall-to-v02727
Jul 8, 2026
Merged

Bump AWF to v0.27.27 and MCPG to v0.4.0#44173
pelikhan merged 6 commits into
mainfrom
copilot/bump-mcpg-to-v040-firewall-to-v02727

Conversation

CopilotAI commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

This updates gh-aw to the latest gh-aw-firewall and gh-aw-mcpg releases, and refreshes the generated artifacts that depend on those image versions and digests.

  • Version bumps

    • Update DefaultFirewallVersion to v0.27.27
    • Update DefaultMCPGatewayVersion to v0.4.0
  • AWF schema sync

    • Refresh the embedded AWF config schema from the v0.27.27 firewall release
    • Carry forward upstream schema additions so gh-aw validates against the current AWF shape
  • Container pin refresh

    • Add the new AWF and MCPG image digests to .github/aw/actions-lock.json
    • Sync the embedded action-pin copies used by compilation/runtime paths
    • Refresh generated workflow lockfiles so they reference the new pinned images
    • Update the AWF firewall pin regression expectations to the new digests, including build-tools for ARC/DinD
  • Generated fixture updates

    • Regenerate wasm golden outputs to reflect the new default AWF version in emitted metadata
  • Release note

    • Add a patch changeset describing the version bump, schema sync, and regenerated pinned artifacts

Example of the version pin update:

constDefaultFirewallVersionVersion="v0.27.27"constDefaultMCPGatewayVersionVersion="v0.4.0"


✨ PR Review Safe Output Test - Run 28918718841

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · 71.3 AIC · ⌖ 31.4 AIC · ⊞ 8.4K ·
Comment /smoke-claude to run again

CopilotAI linked an issue Jul 8, 2026 that may be closed by this pull request
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
CopilotAI changed the title [WIP] Update mcpg to v0.4.0 and firewall to v0.27.27Bump AWF to v0.27.27 and MCPG to v0.4.0Jul 8, 2026
@lpcox
lpcox marked this pull request as ready for review July 8, 2026 04:04
@lpcox
lpcox requested review from CopilotJuly 8, 2026 04:04
CopilotAI requested a review from lpcoxJuly 8, 2026 04:05

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request updates gh-aw’s pinned versions and generated artifacts to align with the latest gh-aw-firewall (AWF) release v0.27.27 and gh-aw-mcpg release v0.4.0, including schema synchronization and regenerated lock/golden fixtures.

Changes:

  • Bump default AWF and MCP Gateway versions, and refresh expected firewall/build-tools digests in regression tests.
  • Sync the embedded AWF config JSON schema with upstream additions/updates (e.g., new vertex target override, container.mounts, expanded Docker field descriptions).
  • Regenerate workflow lockfiles and wasm golden fixtures to reflect the new pinned images and default version metadata.
Show a summary per file
FileDescription
pkg/constants/version_constants.goBumps DefaultFirewallVersion to v0.27.27 and DefaultMCPGatewayVersion to v0.4.0.
pkg/workflow/schemas/awf-config.schema.jsonSyncs embedded AWF config schema with new fields and updated descriptions.
pkg/workflow/docker_firewall_pin_compile_test.goUpdates expected pinned digests for AWF images and build-tools for ARC/DinD.
.github/aw/actions-lock.jsonAdds new pinned image entries for AWF 0.27.27 and MCPG v0.4.0.
pkg/actionpins/data/action_pins.jsonSyncs embedded action pin data with new container digests.
pkg/workflow/data/action_pins.jsonSyncs workflow-side embedded action pin data with new container digests.
.github/workflows/test-workflow.lock.ymlRegenerates lockfile manifest/pins and emitted AWF/MCPG references for the bumped versions.
.github/workflows/ace-editor.lock.ymlRegenerates lockfile manifest/pins and emitted AWF/MCPG references for the bumped versions.
pkg/workflow/testdata/TestWasmGolden_CompileFixtures/with-imports.goldenUpdates wasm golden output metadata and image references to AWF v0.27.27 / MCPG v0.4.0.
pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.goldenUpdates wasm golden output metadata and image references to AWF v0.27.27 / MCPG v0.4.0.
pkg/workflow/testdata/TestWasmGolden_CompileFixtures/playwright-cli-mode.goldenUpdates wasm golden output metadata and image references to AWF v0.27.27 / MCPG v0.4.0.
pkg/workflow/testdata/TestWasmGolden_CompileFixtures/basic-copilot.goldenUpdates wasm golden output metadata and image references to AWF v0.27.27 / MCPG v0.4.0.
pkg/workflow/testdata/TestWasmGolden_AllEngines/pi.goldenUpdates wasm golden output metadata and image references to AWF v0.27.27 / MCPG v0.4.0.
pkg/workflow/testdata/TestWasmGolden_AllEngines/gemini.goldenUpdates wasm golden output metadata and image references to AWF v0.27.27 / MCPG v0.4.0.
pkg/workflow/testdata/TestWasmGolden_AllEngines/copilot.goldenUpdates wasm golden output metadata and image references to AWF v0.27.27 / MCPG v0.4.0.
pkg/workflow/testdata/TestWasmGolden_AllEngines/codex.goldenUpdates wasm golden output metadata and image references to AWF v0.27.27 / MCPG v0.4.0.
pkg/workflow/testdata/TestWasmGolden_AllEngines/claude.goldenUpdates wasm golden output metadata and image references to AWF v0.27.27 / MCPG v0.4.0.
.changeset/patch-bump-awf-v0-27-27-mcpg-v0-4-0.mdAdds a patch changeset describing the version/schema/pin refresh.

Review details

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 31/274 changed files
  • Comments generated: 1
  • Review effort level: Low

@@ -726,7 +738,7 @@
"topology": {
"type": "string",
"enum": ["standard", "arc-dind"],
"description": "Runner deployment topology. 'standard' (default) = GitHub-hosted VM or self-hosted runner with local Docker. 'arc-dind' = ARC (Actions Runner Controller) with Docker-in-Docker sidecar, where the runner and Docker daemon have separate filesystems. When set to 'arc-dind', AWF applies overridable defaults: network.isolation=true, dind.preStageDirs=true, sysroot image activation, and tool cache validation."
"description": "Runner deployment topology. 'standard' (default) = GitHub-hosted VM or self-hosted runner with local Docker. 'arc-dind' = ARC (Actions Runner Controller) with Docker-in-Docker sidecar, where the runner and Docker daemon have separate filesystems. When set to 'arc-dind', AWF enables sysroot staging (a sysroot-stage init container copies the build-tools image into a named volume mounted at /host:rw on the agent) and emits a warning when RUNNER_TOOL_CACHE points under /opt (which is typically invisible to the DinD daemon). Other ARC/DinD settings such as container.dockerHostPathPrefix, dind.preStageDirs, and network.isolation are configured explicitly through their own fields. See docs/arc-dind.md for a complete guide."

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed the See docs/arc-dind.md for a complete guide. sentence from the description — the file doesn't exist in this repo. Fixed in commit $(cd /home/runner/work/gh-aw/gh-aw && git rev-parse --short HEAD).

@lpcox

lpcox commented Jul 8, 2026

Copy link
Copy Markdown
Collaborator

@copilot run pr-finisher skill

CopilotAIand others added 2 commits July 8, 2026 04:23
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
…opology description
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot merge main and recompile

CopilotAIand others added 2 commits July 8, 2026 04:53
…v040-firewall-to-v02727
# Conflicts:
#	.github/workflows/daily-byok-ollama-test.lock.yml
#	.github/workflows/smoke-codex.lock.yml
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

CopilotAI commented Jul 8, 2026

Copy link
Copy Markdown
ContributorAuthor

@copilot merge main and recompile

Done. Merged main (resolved conflicts in two generated lockfiles) and ran make recompile — all 258 workflows compiled cleanly. The recompile also picked up the security fix from main that replaced curl | sh Ollama install with a download+verify pattern.

@github-actions

github-actionsBot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

🎬 THE ENDSmoke ClaudeMISSION: ACCOMPLISHED! The hero saves the day! ✨

@github-actions

github-actionsBot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

@github-actions

github-actionsBot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

🚀 Smoke AntigravityMISSION COMPLETE! Antigravity has spoken. ✨

@github-actions

github-actionsBot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

🚀 Smoke GeminiMISSION COMPLETE! Gemini has spoken. ✨

@github-actions

github-actionsBot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

🚀 Smoke PiMISSION COMPLETE! Pi delivered. 🥧

@github-actions

Copy link
Copy Markdown
Contributor

📰 BREAKING: Smoke Copilot - AOAI (apikey) is now investigating this pull request. Sources say the story is developing...

@github-actions

github-actionsBot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

✅ All tools validated successfully! Agent Container Smoke Test confirms agent container is ready.

@github-actions

Copy link
Copy Markdown
Contributor

📰 BREAKING: Smoke Copilot - AOAI (Entra) is now investigating this pull request. Sources say the story is developing...

@github-actions

Copy link
Copy Markdown
Contributor

📰 BREAKING: Smoke Copilot is now investigating this pull request. Sources say the story is developing...

@github-actions

Copy link
Copy Markdown
Contributor

Smoke test

  • GitHub CLI ✅
  • Web Fetch ❌
  • File/Bash ✅
  • Build ❌
  • Overall: FAIL

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • proxy.golang.org

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "proxy.golang.org"

See Network Configuration for more information.

🥧 Smoke Pi — Powered by Pi · 1.85 AIC · ⌖ 6.96 AIC · ⊞ 4.4K ·
Comment /smoke-pi to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test Results

  • GitHub MCP Testing: ✅
  • Web Fetch Testing: ✅
  • File Writing Testing: ✅
  • Bash Tool Testing: ✅
  • Build gh-aw: ❌

Overall Status: FAIL

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • localhost

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "localhost"

See Network Configuration for more information.

Smoke Gemini — Powered by Gemini · 9.39 AIC · ⌖ 5.25 AIC · ⊞ 9.3K ·
Comment /smoke-gemini to run again

@github-actions

Copy link
Copy Markdown
Contributor

Agent Container Tool Check

ToolStatusVersion
bash5.2.21
shavailable
git2.54.0
jq1.7
yq4.53.3
curl8.5.0
gh2.96.0
node22.23.1
python33.11.15 (PyPy)
go1.24.13
java21.0.11
dotnet10.0.301

Result: 12/12 tools available ✅

Overall Status: PASS

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "awmgmcpg"

See Network Configuration for more information.

🔧 Tool validation by Agent Container Smoke Test · 13.7 AIC · ⌖ 5.58 AIC · ⊞ 4.6K ·
Comment /smoke-test-tools to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke test: FAIL\nMerged PRs: #44183 [log] Add debug logging to parser and workflow files\nMerged PRs: #44171 [community] Update community contributions in README\nGitHub PR read ✅ | Serena ✅ | Playwright ✅ | Web fetch ❌ | Build ✅

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex · 1.13 AIC · ⌖ 1.19 AIC · ⊞ 20.3K ·
Comment /smoke-codex to run again

@github-actions

Copy link
Copy Markdown
Contributor

Comment Memory

Soft checks hum at dawn
Glyphs and caches wake in turn
Smoke drifts, build stays clear

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex · 1.13 AIC · ⌖ 1.19 AIC · ⊞ 20.3K ·
Comment /smoke-codex to run again

@github-actions

Copy link
Copy Markdown
Contributor

💥 Smoke Test: Claude — Run 28918718841

Core #1-12: ✅ all passed
#13 Update PR:#14 Review comments:#15 Submit review:#16 Resolve thread:#17 Add reviewer:
#18 Push to branch:⚠️ skipped (branch history has files outside allowed-files guardrail)
#19 Close PR:⚠️ skipped (no safe test PR)

Overall: PARTIAL (all non-skipped tests passed)

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · 71.3 AIC · ⌖ 31.4 AIC · ⊞ 8.4K ·
Comment /smoke-claude to run again

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💥 Automated smoke test review - all systems nominal!

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · 71.3 AIC · ⌖ 31.4 AIC · ⊞ 8.4K
Comment /smoke-claude to run again

---
"gh-aw": patch
---

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: consider linking the AWF/MCPG release notes here for reviewers to cross-check versions. (smoke test)

"gh-aw": patch
---

Bump the default gh-aw-firewall version to v0.27.27, update gh-aw-mcpg to v0.4.0, sync the embedded AWF config schema, and regenerate pinned workflow artifacts.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Optional: mention regenerated artifacts count so reviewers know the blast radius. (smoke test)

@pelikhan
pelikhan merged commit 95f9025 into mainJul 8, 2026
208 checks passed
@pelikhan
pelikhan deleted the copilot/bump-mcpg-to-v040-firewall-to-v02727 branch July 8, 2026 05:13
@github-actions

Copy link
Copy Markdown
Contributor

Comment Memory

Test drums beat.
Bots poke stone sky.
Smoke run sing true.

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot · 106.9 AIC · ⌖ 5.98 AIC · ⊞ 19.1K ·
Comment /smoke-copilot to run again
Add label smoke to run again

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cave smoke review done. Bumps and pins look lined up.

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot · 106.9 AIC · ⌖ 5.98 AIC · ⊞ 19.1K
Comment /smoke-copilot to run again
Add label smoke to run again

@github-actions

Copy link
Copy Markdown
Contributor

Comment Memory

Silent code whispers
Terminal lights up with life
Smoke tests bring sunrise

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot - AOAI (apikey) · 60.1 AIC · ⌖ 3.87 AIC · ⊞ 17.9K ·
Comment /smoke-copilot-aoai-apikey to run again
Add label smoke to run again

@github-actionsgithub-actionsBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Smoke test review submitted.

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot - AOAI (apikey) · 60.1 AIC · ⌖ 3.87 AIC · ⊞ 17.9K
Comment /smoke-copilot-aoai-apikey to run again
Add label smoke to run again

@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.82.4

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bump mcpg to v0.4.0 and firewall to v0.27.27

4 participants

@lpcox@pelikhan