[main] Bump github/gh-aw/actions/setup from 0.86.0 to 0.86.2 - #10657

Merged
Amaury Levé (Evangelink) merged 1 commit into
mainfrom
dependabot/github_actions/github/gh-aw/actions/setup-0.86.2
Aug 24, 2026
Merged

[main] Bump github/gh-aw/actions/setup from 0.86.0 to 0.86.2#10657
Amaury Levé (Evangelink) merged 1 commit into
mainfrom
dependabot/github_actions/github/gh-aw/actions/setup-0.86.2

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 20, 2026

Copy link
Copy Markdown
Contributor

Bumps github/gh-aw/actions/setup from 0.86.0 to 0.86.2.

Release notes

Sourced from github/gh-aw/actions/setup's releases.

v0.86.2

🌟 Release Highlights

This release focuses on hardening the sandbox and MCP gateway, smoothing out safe-output and threat-detection reliability, and shipping a steady stream of security and quality fixes across the compiler and CLI.

✨ What's New

  • Docker sandbox (docker-sbx) rollout continues — the sandboxed execution environment now runs for a larger share of agentic workflows, with fixes for pre-flight step naming, gVisor false positives, and Docker Hub secret handling (#51264, #51294, #51341, #51439, #51949). See the sandbox reference.
  • Agent runtime trackingsandbox.agent.runtime is now stored in aw_info.json, and gh aw logs/gh aw audit gained a --runtime filter for easier debugging across engines (#51465, #52076). See agent runtimes.
  • MCP gateway hardening — explicit mount policy allowlisting for the safeoutputs backend server, plus a bump to gh-aw-mcpg v0.4.9 and github-mcp-server v1.9.0 (#51870, #51828).
  • Skills frontmatter flexibility — non-SHA refs are now allowed in skills frontmatter and pinned automatically at compile time, and an explicit end-marker syntax was added for inline skills/sub-agents (#51455, #51446).
  • Threat detection improvements — inline threat detection for Code Scanning Fixer, rendered detection logs with group/mask macros, and gh-aw's own <system> prompt block is no longer flagged as prompt injection (#51277, #51255, #51818). See threat detection.

🐛 Bug Fixes & Improvements

  • Fixed silent failures in the Copilot session data fetcher and in gh aw mcp inspect pagination (#51195, #51193).
  • Fixed Claude harness retrying invalid-JSON body errors with --continue instead of starting a fresh run (#51793).
  • Fixed a CGO/CJS workflow cache key collision that caused widespread job failures (#51342).
  • Fixed recurring gh-aw-firewall digest-pin loss on default firewall version bumps (#51423).
  • Fixed Windows MCP server timeouts by propagating context through GitHub CLI subprocess calls (#51426).
  • Fixed retry handling and denials in the Contribution Check proxy (#51631).
  • Added support for HEAD-only bundles when pushing to pull request branches (#51833).
  • Fixed safe-output run summary classification so entries are always linked and correctly attributed (#51484, #51478).

📚 Documentation

  • Documented the --runtime flag for gh aw logs/gh aw audit, agent runtime selection/troubleshooting, and clarified Claude engine selection in automated bootstrap (#52076, #51427, #52099).
  • Improved overall documentation discoverability and trimmed troubleshooting guides (#52065, #51251).

🔧 Internal

A large batch of custom-linter hardening, dependency bumps, test-parallelization, and dependency vulnerability remediations (container image pinning, ip-address patch, deprecated MCP container replacements) round out this release — thanks to the automated maintenance workflows keeping the codebase clean and secure.> Generated by 🚀 Release · auto · 20.7 AIC · ⊞ 11.3K


What's Changed

... (truncated)

Commits
  • 48e5fa3 Clarify Claude engine selection in automated bootstrap (#52099)
  • 9699516 Fix inverted strict: mode documentation in frontmatter reference (#52100)
  • fa5e232 Improve GitHub Agentic Workflows documentation discoverability (#52065)
  • 85f9048 Normalize report formatting in video-analyzer, plan, and centralization-drill...
  • 1dd49c6 Suppress benign workflow exfiltration findings (#52083)
  • c636d5f docs: document --runtime flag for gh aw logs and gh aw audit (#52076)
  • 62647ef Harden scanner/relaunch exec trust boundaries and argument validation (#52032)
  • 9922b2f Harden remote workflow import fallbacks to prevent cross-host downgrade to pu...
  • 81a1321 Remediate dynamic regexp pattern findings (#51941)
  • 485f970 [aw] Reduce Daily PR review tool-denial failures in Copilot SDK runs (#52060)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/gh-aw/actions/setup](https://github.com/github/gh-aw) from 0.86.0 to 0.86.2.
- [Release notes](https://github.com/github/gh-aw/releases)
- [Changelog](https://github.com/github/gh-aw/blob/main/CHANGELOG.md)
- [Commits](github/gh-aw@435186c...48e5fa3)
---
updated-dependencies:
- dependency-name: github/gh-aw/actions/setup
dependency-version: 0.86.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Updates to dependency manifests. github_actions labels Aug 20, 2026
CopilotAI balanced review requested due to automatic review settings August 20, 2026 06:40
@dependabotdependabotBot added dependencies Updates to dependency manifests. github_actions labels Aug 20, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the github/gh-aw/actions/setup pin from 0.86.0 to 0.86.2 across generated agentic workflows.

Changes:

  • Replaces executable setup-action references with the new immutable SHA.
  • Synchronizes generated action inventory comments.

Reviewed changes

Copilot reviewed 29 out of 29 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
.github/workflows/weekly-issue-activity.lock.ymlUpdates setup pin.
.github/workflows/unskip-closed-tests.lock.ymlUpdates setup pin.
.github/workflows/test-reviewer.agent.lock.ymlUpdates setup pin.
.github/workflows/test-reviewer-on-pr.agent.lock.ymlUpdates setup pin.
.github/workflows/test-improver.lock.ymlUpdates setup pin.
.github/workflows/sub-issue-closer.lock.ymlUpdates setup pin.
.github/workflows/review.agent.lock.ymlUpdates setup pin.
.github/workflows/review-on-open.agent.lock.ymlUpdates setup pin.
.github/workflows/review-after-autofix.agent.lock.ymlUpdates setup pin.
.github/workflows/repository-quality-improver.lock.ymlUpdates setup pin.
.github/workflows/pr-fix.lock.ymlUpdates setup pin.
.github/workflows/perf-improver.lock.ymlUpdates setup pin.
.github/workflows/parallel-safety-audit.lock.ymlUpdates setup pin.
.github/workflows/parallel-safety-audit-command.lock.ymlUpdates setup pin.
.github/workflows/msbuild-quality-review.lock.ymlUpdates setup pin.
.github/workflows/markdown-linter.lock.ymlUpdates setup pin.
.github/workflows/malicious-code-scan.lock.ymlUpdates setup pin.
.github/workflows/link-checker.lock.ymlUpdates setup pin.
.github/workflows/glossary-maintainer.lock.ymlUpdates setup pin.
.github/workflows/efficiency-improver.lock.ymlUpdates setup pin.
.github/workflows/duplicate-code-detector.lock.ymlUpdates setup pin.
.github/workflows/dependabot-pr-bundler.lock.ymlUpdates setup pin.
.github/workflows/dependabot-issue-bundler.lock.ymlUpdates setup pin.
.github/workflows/daily-file-diet.lock.ymlUpdates setup pin.
.github/workflows/code-simplifier.lock.ymlUpdates setup pin.
.github/workflows/autofix.agent.lock.ymlUpdates setup pin.
.github/workflows/adhoc-qa.lock.ymlUpdates setup pin.
.github/workflows/address-review.agent.lock.ymlUpdates setup pin.
.github/workflows/add-tests.lock.ymlUpdates setup pin.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Evangelink
Amaury Levé (Evangelink) merged commit d52effb into mainAug 24, 2026
20 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dependabot/github_actions/github/gh-aw/actions/setup-0.86.2 branch August 24, 2026 08:21
Jakub Jareš (nohwnd) added a commit that referenced this pull request Aug 24, 2026
Conflict in .github/workflows/markdown-linter.lock.yml: #10657 bumped the
gh-aw setup pin from 435186c5 to 48e5fa3f across every lock file, while this
branch removed super-linter from the same header block.
Resolved by regenerating the lock file from its .md source with
`gh aw compile --action-mode release --action-tag 48e5fa3f` rather than editing
the generated file, so it picks up the new pin and keeps this branch's changes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesUpdates to dependency manifests.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

[main] Bump github/gh-aw/actions/setup from 0.86.0 to 0.86.2 - #10657

Merged
Amaury Levé (Evangelink) merged 1 commit into
mainfrom
dependabot/github_actions/github/gh-aw/actions/setup-0.86.2
Aug 24, 2026
Merged

[main] Bump github/gh-aw/actions/setup from 0.86.0 to 0.86.2#10657
Amaury Levé (Evangelink) merged 1 commit into
mainfrom
dependabot/github_actions/github/gh-aw/actions/setup-0.86.2

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 20, 2026

Copy link
Copy Markdown
Contributor

Bumps github/gh-aw/actions/setup from 0.86.0 to 0.86.2.

Release notes

Sourced from github/gh-aw/actions/setup's releases.

v0.86.2

🌟 Release Highlights

This release focuses on hardening the sandbox and MCP gateway, smoothing out safe-output and threat-detection reliability, and shipping a steady stream of security and quality fixes across the compiler and CLI.

✨ What's New

  • Docker sandbox (docker-sbx) rollout continues — the sandboxed execution environment now runs for a larger share of agentic workflows, with fixes for pre-flight step naming, gVisor false positives, and Docker Hub secret handling (#51264, #51294, #51341, #51439, #51949). See the sandbox reference.
  • Agent runtime trackingsandbox.agent.runtime is now stored in aw_info.json, and gh aw logs/gh aw audit gained a --runtime filter for easier debugging across engines (#51465, #52076). See agent runtimes.
  • MCP gateway hardening — explicit mount policy allowlisting for the safeoutputs backend server, plus a bump to gh-aw-mcpg v0.4.9 and github-mcp-server v1.9.0 (#51870, #51828).
  • Skills frontmatter flexibility — non-SHA refs are now allowed in skills frontmatter and pinned automatically at compile time, and an explicit end-marker syntax was added for inline skills/sub-agents (#51455, #51446).
  • Threat detection improvements — inline threat detection for Code Scanning Fixer, rendered detection logs with group/mask macros, and gh-aw's own <system> prompt block is no longer flagged as prompt injection (#51277, #51255, #51818). See threat detection.

🐛 Bug Fixes & Improvements

  • Fixed silent failures in the Copilot session data fetcher and in gh aw mcp inspect pagination (#51195, #51193).
  • Fixed Claude harness retrying invalid-JSON body errors with --continue instead of starting a fresh run (#51793).
  • Fixed a CGO/CJS workflow cache key collision that caused widespread job failures (#51342).
  • Fixed recurring gh-aw-firewall digest-pin loss on default firewall version bumps (#51423).
  • Fixed Windows MCP server timeouts by propagating context through GitHub CLI subprocess calls (#51426).
  • Fixed retry handling and denials in the Contribution Check proxy (#51631).
  • Added support for HEAD-only bundles when pushing to pull request branches (#51833).
  • Fixed safe-output run summary classification so entries are always linked and correctly attributed (#51484, #51478).

📚 Documentation

  • Documented the --runtime flag for gh aw logs/gh aw audit, agent runtime selection/troubleshooting, and clarified Claude engine selection in automated bootstrap (#52076, #51427, #52099).
  • Improved overall documentation discoverability and trimmed troubleshooting guides (#52065, #51251).

🔧 Internal

A large batch of custom-linter hardening, dependency bumps, test-parallelization, and dependency vulnerability remediations (container image pinning, ip-address patch, deprecated MCP container replacements) round out this release — thanks to the automated maintenance workflows keeping the codebase clean and secure.> Generated by 🚀 Release · auto · 20.7 AIC · ⊞ 11.3K


What's Changed

... (truncated)

Commits
  • 48e5fa3 Clarify Claude engine selection in automated bootstrap (#52099)
  • 9699516 Fix inverted strict: mode documentation in frontmatter reference (#52100)
  • fa5e232 Improve GitHub Agentic Workflows documentation discoverability (#52065)
  • 85f9048 Normalize report formatting in video-analyzer, plan, and centralization-drill...
  • 1dd49c6 Suppress benign workflow exfiltration findings (#52083)
  • c636d5f docs: document --runtime flag for gh aw logs and gh aw audit (#52076)
  • 62647ef Harden scanner/relaunch exec trust boundaries and argument validation (#52032)
  • 9922b2f Harden remote workflow import fallbacks to prevent cross-host downgrade to pu...
  • 81a1321 Remediate dynamic regexp pattern findings (#51941)
  • 485f970 [aw] Reduce Daily PR review tool-denial failures in Copilot SDK runs (#52060)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/gh-aw/actions/setup](https://github.com/github/gh-aw) from 0.86.0 to 0.86.2.
- [Release notes](https://github.com/github/gh-aw/releases)
- [Changelog](https://github.com/github/gh-aw/blob/main/CHANGELOG.md)
- [Commits](github/gh-aw@435186c...48e5fa3)
---
updated-dependencies:
- dependency-name: github/gh-aw/actions/setup
dependency-version: 0.86.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Updates to dependency manifests. github_actions labels Aug 20, 2026
CopilotAI balanced review requested due to automatic review settings August 20, 2026 06:40
@dependabotdependabotBot added dependencies Updates to dependency manifests. github_actions labels Aug 20, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the github/gh-aw/actions/setup pin from 0.86.0 to 0.86.2 across generated agentic workflows.

Changes:

  • Replaces executable setup-action references with the new immutable SHA.
  • Synchronizes generated action inventory comments.

Reviewed changes

Copilot reviewed 29 out of 29 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
.github/workflows/weekly-issue-activity.lock.ymlUpdates setup pin.
.github/workflows/unskip-closed-tests.lock.ymlUpdates setup pin.
.github/workflows/test-reviewer.agent.lock.ymlUpdates setup pin.
.github/workflows/test-reviewer-on-pr.agent.lock.ymlUpdates setup pin.
.github/workflows/test-improver.lock.ymlUpdates setup pin.
.github/workflows/sub-issue-closer.lock.ymlUpdates setup pin.
.github/workflows/review.agent.lock.ymlUpdates setup pin.
.github/workflows/review-on-open.agent.lock.ymlUpdates setup pin.
.github/workflows/review-after-autofix.agent.lock.ymlUpdates setup pin.
.github/workflows/repository-quality-improver.lock.ymlUpdates setup pin.
.github/workflows/pr-fix.lock.ymlUpdates setup pin.
.github/workflows/perf-improver.lock.ymlUpdates setup pin.
.github/workflows/parallel-safety-audit.lock.ymlUpdates setup pin.
.github/workflows/parallel-safety-audit-command.lock.ymlUpdates setup pin.
.github/workflows/msbuild-quality-review.lock.ymlUpdates setup pin.
.github/workflows/markdown-linter.lock.ymlUpdates setup pin.
.github/workflows/malicious-code-scan.lock.ymlUpdates setup pin.
.github/workflows/link-checker.lock.ymlUpdates setup pin.
.github/workflows/glossary-maintainer.lock.ymlUpdates setup pin.
.github/workflows/efficiency-improver.lock.ymlUpdates setup pin.
.github/workflows/duplicate-code-detector.lock.ymlUpdates setup pin.
.github/workflows/dependabot-pr-bundler.lock.ymlUpdates setup pin.
.github/workflows/dependabot-issue-bundler.lock.ymlUpdates setup pin.
.github/workflows/daily-file-diet.lock.ymlUpdates setup pin.
.github/workflows/code-simplifier.lock.ymlUpdates setup pin.
.github/workflows/autofix.agent.lock.ymlUpdates setup pin.
.github/workflows/adhoc-qa.lock.ymlUpdates setup pin.
.github/workflows/address-review.agent.lock.ymlUpdates setup pin.
.github/workflows/add-tests.lock.ymlUpdates setup pin.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Evangelink
Amaury Levé (Evangelink) merged commit d52effb into mainAug 24, 2026
20 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dependabot/github_actions/github/gh-aw/actions/setup-0.86.2 branch August 24, 2026 08:21
Jakub Jareš (nohwnd) added a commit that referenced this pull request Aug 24, 2026
Conflict in .github/workflows/markdown-linter.lock.yml: #10657 bumped the
gh-aw setup pin from 435186c5 to 48e5fa3f across every lock file, while this
branch removed super-linter from the same header block.
Resolved by regenerating the lock file from its .md source with
`gh aw compile --action-mode release --action-tag 48e5fa3f` rather than editing
the generated file, so it picks up the new pin and keeps this branch's changes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesUpdates to dependency manifests.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[main] Bump github/gh-aw/actions/setup from 0.86.0 to 0.86.2 - #10657

Merged
Amaury Levé (Evangelink) merged 1 commit into
mainfrom
dependabot/github_actions/github/gh-aw/actions/setup-0.86.2
Aug 24, 2026
Merged

[main] Bump github/gh-aw/actions/setup from 0.86.0 to 0.86.2#10657
Amaury Levé (Evangelink) merged 1 commit into
mainfrom
dependabot/github_actions/github/gh-aw/actions/setup-0.86.2

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 20, 2026

Copy link
Copy Markdown
Contributor

Bumps github/gh-aw/actions/setup from 0.86.0 to 0.86.2.

Release notes

Sourced from github/gh-aw/actions/setup's releases.

v0.86.2

🌟 Release Highlights

This release focuses on hardening the sandbox and MCP gateway, smoothing out safe-output and threat-detection reliability, and shipping a steady stream of security and quality fixes across the compiler and CLI.

✨ What's New

  • Docker sandbox (docker-sbx) rollout continues — the sandboxed execution environment now runs for a larger share of agentic workflows, with fixes for pre-flight step naming, gVisor false positives, and Docker Hub secret handling (#51264, #51294, #51341, #51439, #51949). See the sandbox reference.
  • Agent runtime trackingsandbox.agent.runtime is now stored in aw_info.json, and gh aw logs/gh aw audit gained a --runtime filter for easier debugging across engines (#51465, #52076). See agent runtimes.
  • MCP gateway hardening — explicit mount policy allowlisting for the safeoutputs backend server, plus a bump to gh-aw-mcpg v0.4.9 and github-mcp-server v1.9.0 (#51870, #51828).
  • Skills frontmatter flexibility — non-SHA refs are now allowed in skills frontmatter and pinned automatically at compile time, and an explicit end-marker syntax was added for inline skills/sub-agents (#51455, #51446).
  • Threat detection improvements — inline threat detection for Code Scanning Fixer, rendered detection logs with group/mask macros, and gh-aw's own <system> prompt block is no longer flagged as prompt injection (#51277, #51255, #51818). See threat detection.

🐛 Bug Fixes & Improvements

  • Fixed silent failures in the Copilot session data fetcher and in gh aw mcp inspect pagination (#51195, #51193).
  • Fixed Claude harness retrying invalid-JSON body errors with --continue instead of starting a fresh run (#51793).
  • Fixed a CGO/CJS workflow cache key collision that caused widespread job failures (#51342).
  • Fixed recurring gh-aw-firewall digest-pin loss on default firewall version bumps (#51423).
  • Fixed Windows MCP server timeouts by propagating context through GitHub CLI subprocess calls (#51426).
  • Fixed retry handling and denials in the Contribution Check proxy (#51631).
  • Added support for HEAD-only bundles when pushing to pull request branches (#51833).
  • Fixed safe-output run summary classification so entries are always linked and correctly attributed (#51484, #51478).

📚 Documentation

  • Documented the --runtime flag for gh aw logs/gh aw audit, agent runtime selection/troubleshooting, and clarified Claude engine selection in automated bootstrap (#52076, #51427, #52099).
  • Improved overall documentation discoverability and trimmed troubleshooting guides (#52065, #51251).

🔧 Internal

A large batch of custom-linter hardening, dependency bumps, test-parallelization, and dependency vulnerability remediations (container image pinning, ip-address patch, deprecated MCP container replacements) round out this release — thanks to the automated maintenance workflows keeping the codebase clean and secure.> Generated by 🚀 Release · auto · 20.7 AIC · ⊞ 11.3K


What's Changed

... (truncated)

Commits
  • 48e5fa3 Clarify Claude engine selection in automated bootstrap (#52099)
  • 9699516 Fix inverted strict: mode documentation in frontmatter reference (#52100)
  • fa5e232 Improve GitHub Agentic Workflows documentation discoverability (#52065)
  • 85f9048 Normalize report formatting in video-analyzer, plan, and centralization-drill...
  • 1dd49c6 Suppress benign workflow exfiltration findings (#52083)
  • c636d5f docs: document --runtime flag for gh aw logs and gh aw audit (#52076)
  • 62647ef Harden scanner/relaunch exec trust boundaries and argument validation (#52032)
  • 9922b2f Harden remote workflow import fallbacks to prevent cross-host downgrade to pu...
  • 81a1321 Remediate dynamic regexp pattern findings (#51941)
  • 485f970 [aw] Reduce Daily PR review tool-denial failures in Copilot SDK runs (#52060)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/gh-aw/actions/setup](https://github.com/github/gh-aw) from 0.86.0 to 0.86.2.
- [Release notes](https://github.com/github/gh-aw/releases)
- [Changelog](https://github.com/github/gh-aw/blob/main/CHANGELOG.md)
- [Commits](github/gh-aw@435186c...48e5fa3)
---
updated-dependencies:
- dependency-name: github/gh-aw/actions/setup
dependency-version: 0.86.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Updates to dependency manifests. github_actions labels Aug 20, 2026
CopilotAI balanced review requested due to automatic review settings August 20, 2026 06:40
@dependabotdependabotBot added dependencies Updates to dependency manifests. github_actions labels Aug 20, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the github/gh-aw/actions/setup pin from 0.86.0 to 0.86.2 across generated agentic workflows.

Changes:

  • Replaces executable setup-action references with the new immutable SHA.
  • Synchronizes generated action inventory comments.

Reviewed changes

Copilot reviewed 29 out of 29 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
.github/workflows/weekly-issue-activity.lock.ymlUpdates setup pin.
.github/workflows/unskip-closed-tests.lock.ymlUpdates setup pin.
.github/workflows/test-reviewer.agent.lock.ymlUpdates setup pin.
.github/workflows/test-reviewer-on-pr.agent.lock.ymlUpdates setup pin.
.github/workflows/test-improver.lock.ymlUpdates setup pin.
.github/workflows/sub-issue-closer.lock.ymlUpdates setup pin.
.github/workflows/review.agent.lock.ymlUpdates setup pin.
.github/workflows/review-on-open.agent.lock.ymlUpdates setup pin.
.github/workflows/review-after-autofix.agent.lock.ymlUpdates setup pin.
.github/workflows/repository-quality-improver.lock.ymlUpdates setup pin.
.github/workflows/pr-fix.lock.ymlUpdates setup pin.
.github/workflows/perf-improver.lock.ymlUpdates setup pin.
.github/workflows/parallel-safety-audit.lock.ymlUpdates setup pin.
.github/workflows/parallel-safety-audit-command.lock.ymlUpdates setup pin.
.github/workflows/msbuild-quality-review.lock.ymlUpdates setup pin.
.github/workflows/markdown-linter.lock.ymlUpdates setup pin.
.github/workflows/malicious-code-scan.lock.ymlUpdates setup pin.
.github/workflows/link-checker.lock.ymlUpdates setup pin.
.github/workflows/glossary-maintainer.lock.ymlUpdates setup pin.
.github/workflows/efficiency-improver.lock.ymlUpdates setup pin.
.github/workflows/duplicate-code-detector.lock.ymlUpdates setup pin.
.github/workflows/dependabot-pr-bundler.lock.ymlUpdates setup pin.
.github/workflows/dependabot-issue-bundler.lock.ymlUpdates setup pin.
.github/workflows/daily-file-diet.lock.ymlUpdates setup pin.
.github/workflows/code-simplifier.lock.ymlUpdates setup pin.
.github/workflows/autofix.agent.lock.ymlUpdates setup pin.
.github/workflows/adhoc-qa.lock.ymlUpdates setup pin.
.github/workflows/address-review.agent.lock.ymlUpdates setup pin.
.github/workflows/add-tests.lock.ymlUpdates setup pin.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Evangelink
Amaury Levé (Evangelink) merged commit d52effb into mainAug 24, 2026
20 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dependabot/github_actions/github/gh-aw/actions/setup-0.86.2 branch August 24, 2026 08:21
Jakub Jareš (nohwnd) added a commit that referenced this pull request Aug 24, 2026
Conflict in .github/workflows/markdown-linter.lock.yml: #10657 bumped the
gh-aw setup pin from 435186c5 to 48e5fa3f across every lock file, while this
branch removed super-linter from the same header block.
Resolved by regenerating the lock file from its .md source with
`gh aw compile --action-mode release --action-tag 48e5fa3f` rather than editing
the generated file, so it picks up the new pin and keeps this branch's changes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesUpdates to dependency manifests.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[main] Bump github/gh-aw/actions/setup from 0.86.0 to 0.86.2 - #10657

Merged
Amaury Levé (Evangelink) merged 1 commit into
mainfrom
dependabot/github_actions/github/gh-aw/actions/setup-0.86.2
Aug 24, 2026
Merged

[main] Bump github/gh-aw/actions/setup from 0.86.0 to 0.86.2#10657
Amaury Levé (Evangelink) merged 1 commit into
mainfrom
dependabot/github_actions/github/gh-aw/actions/setup-0.86.2

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 20, 2026

Copy link
Copy Markdown
Contributor

Bumps github/gh-aw/actions/setup from 0.86.0 to 0.86.2.

Release notes

Sourced from github/gh-aw/actions/setup's releases.

v0.86.2

🌟 Release Highlights

This release focuses on hardening the sandbox and MCP gateway, smoothing out safe-output and threat-detection reliability, and shipping a steady stream of security and quality fixes across the compiler and CLI.

✨ What's New

  • Docker sandbox (docker-sbx) rollout continues — the sandboxed execution environment now runs for a larger share of agentic workflows, with fixes for pre-flight step naming, gVisor false positives, and Docker Hub secret handling (#51264, #51294, #51341, #51439, #51949). See the sandbox reference.
  • Agent runtime trackingsandbox.agent.runtime is now stored in aw_info.json, and gh aw logs/gh aw audit gained a --runtime filter for easier debugging across engines (#51465, #52076). See agent runtimes.
  • MCP gateway hardening — explicit mount policy allowlisting for the safeoutputs backend server, plus a bump to gh-aw-mcpg v0.4.9 and github-mcp-server v1.9.0 (#51870, #51828).
  • Skills frontmatter flexibility — non-SHA refs are now allowed in skills frontmatter and pinned automatically at compile time, and an explicit end-marker syntax was added for inline skills/sub-agents (#51455, #51446).
  • Threat detection improvements — inline threat detection for Code Scanning Fixer, rendered detection logs with group/mask macros, and gh-aw's own <system> prompt block is no longer flagged as prompt injection (#51277, #51255, #51818). See threat detection.

🐛 Bug Fixes & Improvements

  • Fixed silent failures in the Copilot session data fetcher and in gh aw mcp inspect pagination (#51195, #51193).
  • Fixed Claude harness retrying invalid-JSON body errors with --continue instead of starting a fresh run (#51793).
  • Fixed a CGO/CJS workflow cache key collision that caused widespread job failures (#51342).
  • Fixed recurring gh-aw-firewall digest-pin loss on default firewall version bumps (#51423).
  • Fixed Windows MCP server timeouts by propagating context through GitHub CLI subprocess calls (#51426).
  • Fixed retry handling and denials in the Contribution Check proxy (#51631).
  • Added support for HEAD-only bundles when pushing to pull request branches (#51833).
  • Fixed safe-output run summary classification so entries are always linked and correctly attributed (#51484, #51478).

📚 Documentation

  • Documented the --runtime flag for gh aw logs/gh aw audit, agent runtime selection/troubleshooting, and clarified Claude engine selection in automated bootstrap (#52076, #51427, #52099).
  • Improved overall documentation discoverability and trimmed troubleshooting guides (#52065, #51251).

🔧 Internal

A large batch of custom-linter hardening, dependency bumps, test-parallelization, and dependency vulnerability remediations (container image pinning, ip-address patch, deprecated MCP container replacements) round out this release — thanks to the automated maintenance workflows keeping the codebase clean and secure.> Generated by 🚀 Release · auto · 20.7 AIC · ⊞ 11.3K


What's Changed

... (truncated)

Commits
  • 48e5fa3 Clarify Claude engine selection in automated bootstrap (#52099)
  • 9699516 Fix inverted strict: mode documentation in frontmatter reference (#52100)
  • fa5e232 Improve GitHub Agentic Workflows documentation discoverability (#52065)
  • 85f9048 Normalize report formatting in video-analyzer, plan, and centralization-drill...
  • 1dd49c6 Suppress benign workflow exfiltration findings (#52083)
  • c636d5f docs: document --runtime flag for gh aw logs and gh aw audit (#52076)
  • 62647ef Harden scanner/relaunch exec trust boundaries and argument validation (#52032)
  • 9922b2f Harden remote workflow import fallbacks to prevent cross-host downgrade to pu...
  • 81a1321 Remediate dynamic regexp pattern findings (#51941)
  • 485f970 [aw] Reduce Daily PR review tool-denial failures in Copilot SDK runs (#52060)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/gh-aw/actions/setup](https://github.com/github/gh-aw) from 0.86.0 to 0.86.2.
- [Release notes](https://github.com/github/gh-aw/releases)
- [Changelog](https://github.com/github/gh-aw/blob/main/CHANGELOG.md)
- [Commits](github/gh-aw@435186c...48e5fa3)
---
updated-dependencies:
- dependency-name: github/gh-aw/actions/setup
dependency-version: 0.86.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Updates to dependency manifests. github_actions labels Aug 20, 2026
CopilotAI balanced review requested due to automatic review settings August 20, 2026 06:40
@dependabotdependabotBot added dependencies Updates to dependency manifests. github_actions labels Aug 20, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the github/gh-aw/actions/setup pin from 0.86.0 to 0.86.2 across generated agentic workflows.

Changes:

  • Replaces executable setup-action references with the new immutable SHA.
  • Synchronizes generated action inventory comments.

Reviewed changes

Copilot reviewed 29 out of 29 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
.github/workflows/weekly-issue-activity.lock.ymlUpdates setup pin.
.github/workflows/unskip-closed-tests.lock.ymlUpdates setup pin.
.github/workflows/test-reviewer.agent.lock.ymlUpdates setup pin.
.github/workflows/test-reviewer-on-pr.agent.lock.ymlUpdates setup pin.
.github/workflows/test-improver.lock.ymlUpdates setup pin.
.github/workflows/sub-issue-closer.lock.ymlUpdates setup pin.
.github/workflows/review.agent.lock.ymlUpdates setup pin.
.github/workflows/review-on-open.agent.lock.ymlUpdates setup pin.
.github/workflows/review-after-autofix.agent.lock.ymlUpdates setup pin.
.github/workflows/repository-quality-improver.lock.ymlUpdates setup pin.
.github/workflows/pr-fix.lock.ymlUpdates setup pin.
.github/workflows/perf-improver.lock.ymlUpdates setup pin.
.github/workflows/parallel-safety-audit.lock.ymlUpdates setup pin.
.github/workflows/parallel-safety-audit-command.lock.ymlUpdates setup pin.
.github/workflows/msbuild-quality-review.lock.ymlUpdates setup pin.
.github/workflows/markdown-linter.lock.ymlUpdates setup pin.
.github/workflows/malicious-code-scan.lock.ymlUpdates setup pin.
.github/workflows/link-checker.lock.ymlUpdates setup pin.
.github/workflows/glossary-maintainer.lock.ymlUpdates setup pin.
.github/workflows/efficiency-improver.lock.ymlUpdates setup pin.
.github/workflows/duplicate-code-detector.lock.ymlUpdates setup pin.
.github/workflows/dependabot-pr-bundler.lock.ymlUpdates setup pin.
.github/workflows/dependabot-issue-bundler.lock.ymlUpdates setup pin.
.github/workflows/daily-file-diet.lock.ymlUpdates setup pin.
.github/workflows/code-simplifier.lock.ymlUpdates setup pin.
.github/workflows/autofix.agent.lock.ymlUpdates setup pin.
.github/workflows/adhoc-qa.lock.ymlUpdates setup pin.
.github/workflows/address-review.agent.lock.ymlUpdates setup pin.
.github/workflows/add-tests.lock.ymlUpdates setup pin.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Evangelink
Amaury Levé (Evangelink) merged commit d52effb into mainAug 24, 2026
20 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dependabot/github_actions/github/gh-aw/actions/setup-0.86.2 branch August 24, 2026 08:21
Jakub Jareš (nohwnd) added a commit that referenced this pull request Aug 24, 2026
Conflict in .github/workflows/markdown-linter.lock.yml: #10657 bumped the
gh-aw setup pin from 435186c5 to 48e5fa3f across every lock file, while this
branch removed super-linter from the same header block.
Resolved by regenerating the lock file from its .md source with
`gh aw compile --action-mode release --action-tag 48e5fa3f` rather than editing
the generated file, so it picks up the new pin and keeps this branch's changes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesUpdates to dependency manifests.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

[main] Bump github/gh-aw/actions/setup from 0.86.0 to 0.86.2 - #10657

Merged
Amaury Levé (Evangelink) merged 1 commit into
mainfrom
dependabot/github_actions/github/gh-aw/actions/setup-0.86.2
Aug 24, 2026
Merged

[main] Bump github/gh-aw/actions/setup from 0.86.0 to 0.86.2#10657
Amaury Levé (Evangelink) merged 1 commit into
mainfrom
dependabot/github_actions/github/gh-aw/actions/setup-0.86.2

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 20, 2026

Copy link
Copy Markdown
Contributor

Bumps github/gh-aw/actions/setup from 0.86.0 to 0.86.2.

Release notes

Sourced from github/gh-aw/actions/setup's releases.

v0.86.2

🌟 Release Highlights

This release focuses on hardening the sandbox and MCP gateway, smoothing out safe-output and threat-detection reliability, and shipping a steady stream of security and quality fixes across the compiler and CLI.

✨ What's New

  • Docker sandbox (docker-sbx) rollout continues — the sandboxed execution environment now runs for a larger share of agentic workflows, with fixes for pre-flight step naming, gVisor false positives, and Docker Hub secret handling (#51264, #51294, #51341, #51439, #51949). See the sandbox reference.
  • Agent runtime trackingsandbox.agent.runtime is now stored in aw_info.json, and gh aw logs/gh aw audit gained a --runtime filter for easier debugging across engines (#51465, #52076). See agent runtimes.
  • MCP gateway hardening — explicit mount policy allowlisting for the safeoutputs backend server, plus a bump to gh-aw-mcpg v0.4.9 and github-mcp-server v1.9.0 (#51870, #51828).
  • Skills frontmatter flexibility — non-SHA refs are now allowed in skills frontmatter and pinned automatically at compile time, and an explicit end-marker syntax was added for inline skills/sub-agents (#51455, #51446).
  • Threat detection improvements — inline threat detection for Code Scanning Fixer, rendered detection logs with group/mask macros, and gh-aw's own <system> prompt block is no longer flagged as prompt injection (#51277, #51255, #51818). See threat detection.

🐛 Bug Fixes & Improvements

  • Fixed silent failures in the Copilot session data fetcher and in gh aw mcp inspect pagination (#51195, #51193).
  • Fixed Claude harness retrying invalid-JSON body errors with --continue instead of starting a fresh run (#51793).
  • Fixed a CGO/CJS workflow cache key collision that caused widespread job failures (#51342).
  • Fixed recurring gh-aw-firewall digest-pin loss on default firewall version bumps (#51423).
  • Fixed Windows MCP server timeouts by propagating context through GitHub CLI subprocess calls (#51426).
  • Fixed retry handling and denials in the Contribution Check proxy (#51631).
  • Added support for HEAD-only bundles when pushing to pull request branches (#51833).
  • Fixed safe-output run summary classification so entries are always linked and correctly attributed (#51484, #51478).

📚 Documentation

  • Documented the --runtime flag for gh aw logs/gh aw audit, agent runtime selection/troubleshooting, and clarified Claude engine selection in automated bootstrap (#52076, #51427, #52099).
  • Improved overall documentation discoverability and trimmed troubleshooting guides (#52065, #51251).

🔧 Internal

A large batch of custom-linter hardening, dependency bumps, test-parallelization, and dependency vulnerability remediations (container image pinning, ip-address patch, deprecated MCP container replacements) round out this release — thanks to the automated maintenance workflows keeping the codebase clean and secure.> Generated by 🚀 Release · auto · 20.7 AIC · ⊞ 11.3K


What's Changed

... (truncated)

Commits
  • 48e5fa3 Clarify Claude engine selection in automated bootstrap (#52099)
  • 9699516 Fix inverted strict: mode documentation in frontmatter reference (#52100)
  • fa5e232 Improve GitHub Agentic Workflows documentation discoverability (#52065)
  • 85f9048 Normalize report formatting in video-analyzer, plan, and centralization-drill...
  • 1dd49c6 Suppress benign workflow exfiltration findings (#52083)
  • c636d5f docs: document --runtime flag for gh aw logs and gh aw audit (#52076)
  • 62647ef Harden scanner/relaunch exec trust boundaries and argument validation (#52032)
  • 9922b2f Harden remote workflow import fallbacks to prevent cross-host downgrade to pu...
  • 81a1321 Remediate dynamic regexp pattern findings (#51941)
  • 485f970 [aw] Reduce Daily PR review tool-denial failures in Copilot SDK runs (#52060)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/gh-aw/actions/setup](https://github.com/github/gh-aw) from 0.86.0 to 0.86.2.
- [Release notes](https://github.com/github/gh-aw/releases)
- [Changelog](https://github.com/github/gh-aw/blob/main/CHANGELOG.md)
- [Commits](github/gh-aw@435186c...48e5fa3)
---
updated-dependencies:
- dependency-name: github/gh-aw/actions/setup
dependency-version: 0.86.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Updates to dependency manifests. github_actions labels Aug 20, 2026
CopilotAI balanced review requested due to automatic review settings August 20, 2026 06:40
@dependabotdependabotBot added dependencies Updates to dependency manifests. github_actions labels Aug 20, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the github/gh-aw/actions/setup pin from 0.86.0 to 0.86.2 across generated agentic workflows.

Changes:

  • Replaces executable setup-action references with the new immutable SHA.
  • Synchronizes generated action inventory comments.

Reviewed changes

Copilot reviewed 29 out of 29 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
.github/workflows/weekly-issue-activity.lock.ymlUpdates setup pin.
.github/workflows/unskip-closed-tests.lock.ymlUpdates setup pin.
.github/workflows/test-reviewer.agent.lock.ymlUpdates setup pin.
.github/workflows/test-reviewer-on-pr.agent.lock.ymlUpdates setup pin.
.github/workflows/test-improver.lock.ymlUpdates setup pin.
.github/workflows/sub-issue-closer.lock.ymlUpdates setup pin.
.github/workflows/review.agent.lock.ymlUpdates setup pin.
.github/workflows/review-on-open.agent.lock.ymlUpdates setup pin.
.github/workflows/review-after-autofix.agent.lock.ymlUpdates setup pin.
.github/workflows/repository-quality-improver.lock.ymlUpdates setup pin.
.github/workflows/pr-fix.lock.ymlUpdates setup pin.
.github/workflows/perf-improver.lock.ymlUpdates setup pin.
.github/workflows/parallel-safety-audit.lock.ymlUpdates setup pin.
.github/workflows/parallel-safety-audit-command.lock.ymlUpdates setup pin.
.github/workflows/msbuild-quality-review.lock.ymlUpdates setup pin.
.github/workflows/markdown-linter.lock.ymlUpdates setup pin.
.github/workflows/malicious-code-scan.lock.ymlUpdates setup pin.
.github/workflows/link-checker.lock.ymlUpdates setup pin.
.github/workflows/glossary-maintainer.lock.ymlUpdates setup pin.
.github/workflows/efficiency-improver.lock.ymlUpdates setup pin.
.github/workflows/duplicate-code-detector.lock.ymlUpdates setup pin.
.github/workflows/dependabot-pr-bundler.lock.ymlUpdates setup pin.
.github/workflows/dependabot-issue-bundler.lock.ymlUpdates setup pin.
.github/workflows/daily-file-diet.lock.ymlUpdates setup pin.
.github/workflows/code-simplifier.lock.ymlUpdates setup pin.
.github/workflows/autofix.agent.lock.ymlUpdates setup pin.
.github/workflows/adhoc-qa.lock.ymlUpdates setup pin.
.github/workflows/address-review.agent.lock.ymlUpdates setup pin.
.github/workflows/add-tests.lock.ymlUpdates setup pin.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Evangelink
Amaury Levé (Evangelink) merged commit d52effb into mainAug 24, 2026
20 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dependabot/github_actions/github/gh-aw/actions/setup-0.86.2 branch August 24, 2026 08:21
Jakub Jareš (nohwnd) added a commit that referenced this pull request Aug 24, 2026
Conflict in .github/workflows/markdown-linter.lock.yml: #10657 bumped the
gh-aw setup pin from 435186c5 to 48e5fa3f across every lock file, while this
branch removed super-linter from the same header block.
Resolved by regenerating the lock file from its .md source with
`gh aw compile --action-mode release --action-tag 48e5fa3f` rather than editing
the generated file, so it picks up the new pin and keeps this branch's changes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesUpdates to dependency manifests.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[main] Bump github/gh-aw/actions/setup from 0.86.0 to 0.86.2 - #10657

Merged
Amaury Levé (Evangelink) merged 1 commit into
mainfrom
dependabot/github_actions/github/gh-aw/actions/setup-0.86.2
Aug 24, 2026
Merged

[main] Bump github/gh-aw/actions/setup from 0.86.0 to 0.86.2#10657
Amaury Levé (Evangelink) merged 1 commit into
mainfrom
dependabot/github_actions/github/gh-aw/actions/setup-0.86.2

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 20, 2026

Copy link
Copy Markdown
Contributor

Bumps github/gh-aw/actions/setup from 0.86.0 to 0.86.2.

Release notes

Sourced from github/gh-aw/actions/setup's releases.

v0.86.2

🌟 Release Highlights

This release focuses on hardening the sandbox and MCP gateway, smoothing out safe-output and threat-detection reliability, and shipping a steady stream of security and quality fixes across the compiler and CLI.

✨ What's New

  • Docker sandbox (docker-sbx) rollout continues — the sandboxed execution environment now runs for a larger share of agentic workflows, with fixes for pre-flight step naming, gVisor false positives, and Docker Hub secret handling (#51264, #51294, #51341, #51439, #51949). See the sandbox reference.
  • Agent runtime trackingsandbox.agent.runtime is now stored in aw_info.json, and gh aw logs/gh aw audit gained a --runtime filter for easier debugging across engines (#51465, #52076). See agent runtimes.
  • MCP gateway hardening — explicit mount policy allowlisting for the safeoutputs backend server, plus a bump to gh-aw-mcpg v0.4.9 and github-mcp-server v1.9.0 (#51870, #51828).
  • Skills frontmatter flexibility — non-SHA refs are now allowed in skills frontmatter and pinned automatically at compile time, and an explicit end-marker syntax was added for inline skills/sub-agents (#51455, #51446).
  • Threat detection improvements — inline threat detection for Code Scanning Fixer, rendered detection logs with group/mask macros, and gh-aw's own <system> prompt block is no longer flagged as prompt injection (#51277, #51255, #51818). See threat detection.

🐛 Bug Fixes & Improvements

  • Fixed silent failures in the Copilot session data fetcher and in gh aw mcp inspect pagination (#51195, #51193).
  • Fixed Claude harness retrying invalid-JSON body errors with --continue instead of starting a fresh run (#51793).
  • Fixed a CGO/CJS workflow cache key collision that caused widespread job failures (#51342).
  • Fixed recurring gh-aw-firewall digest-pin loss on default firewall version bumps (#51423).
  • Fixed Windows MCP server timeouts by propagating context through GitHub CLI subprocess calls (#51426).
  • Fixed retry handling and denials in the Contribution Check proxy (#51631).
  • Added support for HEAD-only bundles when pushing to pull request branches (#51833).
  • Fixed safe-output run summary classification so entries are always linked and correctly attributed (#51484, #51478).

📚 Documentation

  • Documented the --runtime flag for gh aw logs/gh aw audit, agent runtime selection/troubleshooting, and clarified Claude engine selection in automated bootstrap (#52076, #51427, #52099).
  • Improved overall documentation discoverability and trimmed troubleshooting guides (#52065, #51251).

🔧 Internal

A large batch of custom-linter hardening, dependency bumps, test-parallelization, and dependency vulnerability remediations (container image pinning, ip-address patch, deprecated MCP container replacements) round out this release — thanks to the automated maintenance workflows keeping the codebase clean and secure.> Generated by 🚀 Release · auto · 20.7 AIC · ⊞ 11.3K


What's Changed

... (truncated)

Commits
  • 48e5fa3 Clarify Claude engine selection in automated bootstrap (#52099)
  • 9699516 Fix inverted strict: mode documentation in frontmatter reference (#52100)
  • fa5e232 Improve GitHub Agentic Workflows documentation discoverability (#52065)
  • 85f9048 Normalize report formatting in video-analyzer, plan, and centralization-drill...
  • 1dd49c6 Suppress benign workflow exfiltration findings (#52083)
  • c636d5f docs: document --runtime flag for gh aw logs and gh aw audit (#52076)
  • 62647ef Harden scanner/relaunch exec trust boundaries and argument validation (#52032)
  • 9922b2f Harden remote workflow import fallbacks to prevent cross-host downgrade to pu...
  • 81a1321 Remediate dynamic regexp pattern findings (#51941)
  • 485f970 [aw] Reduce Daily PR review tool-denial failures in Copilot SDK runs (#52060)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/gh-aw/actions/setup](https://github.com/github/gh-aw) from 0.86.0 to 0.86.2.
- [Release notes](https://github.com/github/gh-aw/releases)
- [Changelog](https://github.com/github/gh-aw/blob/main/CHANGELOG.md)
- [Commits](github/gh-aw@435186c...48e5fa3)
---
updated-dependencies:
- dependency-name: github/gh-aw/actions/setup
dependency-version: 0.86.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Updates to dependency manifests. github_actions labels Aug 20, 2026
CopilotAI balanced review requested due to automatic review settings August 20, 2026 06:40
@dependabotdependabotBot added dependencies Updates to dependency manifests. github_actions labels Aug 20, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the github/gh-aw/actions/setup pin from 0.86.0 to 0.86.2 across generated agentic workflows.

Changes:

  • Replaces executable setup-action references with the new immutable SHA.
  • Synchronizes generated action inventory comments.

Reviewed changes

Copilot reviewed 29 out of 29 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
.github/workflows/weekly-issue-activity.lock.ymlUpdates setup pin.
.github/workflows/unskip-closed-tests.lock.ymlUpdates setup pin.
.github/workflows/test-reviewer.agent.lock.ymlUpdates setup pin.
.github/workflows/test-reviewer-on-pr.agent.lock.ymlUpdates setup pin.
.github/workflows/test-improver.lock.ymlUpdates setup pin.
.github/workflows/sub-issue-closer.lock.ymlUpdates setup pin.
.github/workflows/review.agent.lock.ymlUpdates setup pin.
.github/workflows/review-on-open.agent.lock.ymlUpdates setup pin.
.github/workflows/review-after-autofix.agent.lock.ymlUpdates setup pin.
.github/workflows/repository-quality-improver.lock.ymlUpdates setup pin.
.github/workflows/pr-fix.lock.ymlUpdates setup pin.
.github/workflows/perf-improver.lock.ymlUpdates setup pin.
.github/workflows/parallel-safety-audit.lock.ymlUpdates setup pin.
.github/workflows/parallel-safety-audit-command.lock.ymlUpdates setup pin.
.github/workflows/msbuild-quality-review.lock.ymlUpdates setup pin.
.github/workflows/markdown-linter.lock.ymlUpdates setup pin.
.github/workflows/malicious-code-scan.lock.ymlUpdates setup pin.
.github/workflows/link-checker.lock.ymlUpdates setup pin.
.github/workflows/glossary-maintainer.lock.ymlUpdates setup pin.
.github/workflows/efficiency-improver.lock.ymlUpdates setup pin.
.github/workflows/duplicate-code-detector.lock.ymlUpdates setup pin.
.github/workflows/dependabot-pr-bundler.lock.ymlUpdates setup pin.
.github/workflows/dependabot-issue-bundler.lock.ymlUpdates setup pin.
.github/workflows/daily-file-diet.lock.ymlUpdates setup pin.
.github/workflows/code-simplifier.lock.ymlUpdates setup pin.
.github/workflows/autofix.agent.lock.ymlUpdates setup pin.
.github/workflows/adhoc-qa.lock.ymlUpdates setup pin.
.github/workflows/address-review.agent.lock.ymlUpdates setup pin.
.github/workflows/add-tests.lock.ymlUpdates setup pin.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Evangelink
Amaury Levé (Evangelink) merged commit d52effb into mainAug 24, 2026
20 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dependabot/github_actions/github/gh-aw/actions/setup-0.86.2 branch August 24, 2026 08:21
Jakub Jareš (nohwnd) added a commit that referenced this pull request Aug 24, 2026
Conflict in .github/workflows/markdown-linter.lock.yml: #10657 bumped the
gh-aw setup pin from 435186c5 to 48e5fa3f across every lock file, while this
branch removed super-linter from the same header block.
Resolved by regenerating the lock file from its .md source with
`gh aw compile --action-mode release --action-tag 48e5fa3f` rather than editing
the generated file, so it picks up the new pin and keeps this branch's changes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesUpdates to dependency manifests.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[main] Bump github/gh-aw/actions/setup from 0.86.0 to 0.86.2 - #10657

Merged
Amaury Levé (Evangelink) merged 1 commit into
mainfrom
dependabot/github_actions/github/gh-aw/actions/setup-0.86.2
Aug 24, 2026
Merged

[main] Bump github/gh-aw/actions/setup from 0.86.0 to 0.86.2#10657
Amaury Levé (Evangelink) merged 1 commit into
mainfrom
dependabot/github_actions/github/gh-aw/actions/setup-0.86.2

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 20, 2026

Copy link
Copy Markdown
Contributor

Bumps github/gh-aw/actions/setup from 0.86.0 to 0.86.2.

Release notes

Sourced from github/gh-aw/actions/setup's releases.

v0.86.2

🌟 Release Highlights

This release focuses on hardening the sandbox and MCP gateway, smoothing out safe-output and threat-detection reliability, and shipping a steady stream of security and quality fixes across the compiler and CLI.

✨ What's New

  • Docker sandbox (docker-sbx) rollout continues — the sandboxed execution environment now runs for a larger share of agentic workflows, with fixes for pre-flight step naming, gVisor false positives, and Docker Hub secret handling (#51264, #51294, #51341, #51439, #51949). See the sandbox reference.
  • Agent runtime trackingsandbox.agent.runtime is now stored in aw_info.json, and gh aw logs/gh aw audit gained a --runtime filter for easier debugging across engines (#51465, #52076). See agent runtimes.
  • MCP gateway hardening — explicit mount policy allowlisting for the safeoutputs backend server, plus a bump to gh-aw-mcpg v0.4.9 and github-mcp-server v1.9.0 (#51870, #51828).
  • Skills frontmatter flexibility — non-SHA refs are now allowed in skills frontmatter and pinned automatically at compile time, and an explicit end-marker syntax was added for inline skills/sub-agents (#51455, #51446).
  • Threat detection improvements — inline threat detection for Code Scanning Fixer, rendered detection logs with group/mask macros, and gh-aw's own <system> prompt block is no longer flagged as prompt injection (#51277, #51255, #51818). See threat detection.

🐛 Bug Fixes & Improvements

  • Fixed silent failures in the Copilot session data fetcher and in gh aw mcp inspect pagination (#51195, #51193).
  • Fixed Claude harness retrying invalid-JSON body errors with --continue instead of starting a fresh run (#51793).
  • Fixed a CGO/CJS workflow cache key collision that caused widespread job failures (#51342).
  • Fixed recurring gh-aw-firewall digest-pin loss on default firewall version bumps (#51423).
  • Fixed Windows MCP server timeouts by propagating context through GitHub CLI subprocess calls (#51426).
  • Fixed retry handling and denials in the Contribution Check proxy (#51631).
  • Added support for HEAD-only bundles when pushing to pull request branches (#51833).
  • Fixed safe-output run summary classification so entries are always linked and correctly attributed (#51484, #51478).

📚 Documentation

  • Documented the --runtime flag for gh aw logs/gh aw audit, agent runtime selection/troubleshooting, and clarified Claude engine selection in automated bootstrap (#52076, #51427, #52099).
  • Improved overall documentation discoverability and trimmed troubleshooting guides (#52065, #51251).

🔧 Internal

A large batch of custom-linter hardening, dependency bumps, test-parallelization, and dependency vulnerability remediations (container image pinning, ip-address patch, deprecated MCP container replacements) round out this release — thanks to the automated maintenance workflows keeping the codebase clean and secure.> Generated by 🚀 Release · auto · 20.7 AIC · ⊞ 11.3K


What's Changed

... (truncated)

Commits
  • 48e5fa3 Clarify Claude engine selection in automated bootstrap (#52099)
  • 9699516 Fix inverted strict: mode documentation in frontmatter reference (#52100)
  • fa5e232 Improve GitHub Agentic Workflows documentation discoverability (#52065)
  • 85f9048 Normalize report formatting in video-analyzer, plan, and centralization-drill...
  • 1dd49c6 Suppress benign workflow exfiltration findings (#52083)
  • c636d5f docs: document --runtime flag for gh aw logs and gh aw audit (#52076)
  • 62647ef Harden scanner/relaunch exec trust boundaries and argument validation (#52032)
  • 9922b2f Harden remote workflow import fallbacks to prevent cross-host downgrade to pu...
  • 81a1321 Remediate dynamic regexp pattern findings (#51941)
  • 485f970 [aw] Reduce Daily PR review tool-denial failures in Copilot SDK runs (#52060)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/gh-aw/actions/setup](https://github.com/github/gh-aw) from 0.86.0 to 0.86.2.
- [Release notes](https://github.com/github/gh-aw/releases)
- [Changelog](https://github.com/github/gh-aw/blob/main/CHANGELOG.md)
- [Commits](github/gh-aw@435186c...48e5fa3)
---
updated-dependencies:
- dependency-name: github/gh-aw/actions/setup
dependency-version: 0.86.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Updates to dependency manifests. github_actions labels Aug 20, 2026
CopilotAI balanced review requested due to automatic review settings August 20, 2026 06:40
@dependabotdependabotBot added dependencies Updates to dependency manifests. github_actions labels Aug 20, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the github/gh-aw/actions/setup pin from 0.86.0 to 0.86.2 across generated agentic workflows.

Changes:

  • Replaces executable setup-action references with the new immutable SHA.
  • Synchronizes generated action inventory comments.

Reviewed changes

Copilot reviewed 29 out of 29 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
.github/workflows/weekly-issue-activity.lock.ymlUpdates setup pin.
.github/workflows/unskip-closed-tests.lock.ymlUpdates setup pin.
.github/workflows/test-reviewer.agent.lock.ymlUpdates setup pin.
.github/workflows/test-reviewer-on-pr.agent.lock.ymlUpdates setup pin.
.github/workflows/test-improver.lock.ymlUpdates setup pin.
.github/workflows/sub-issue-closer.lock.ymlUpdates setup pin.
.github/workflows/review.agent.lock.ymlUpdates setup pin.
.github/workflows/review-on-open.agent.lock.ymlUpdates setup pin.
.github/workflows/review-after-autofix.agent.lock.ymlUpdates setup pin.
.github/workflows/repository-quality-improver.lock.ymlUpdates setup pin.
.github/workflows/pr-fix.lock.ymlUpdates setup pin.
.github/workflows/perf-improver.lock.ymlUpdates setup pin.
.github/workflows/parallel-safety-audit.lock.ymlUpdates setup pin.
.github/workflows/parallel-safety-audit-command.lock.ymlUpdates setup pin.
.github/workflows/msbuild-quality-review.lock.ymlUpdates setup pin.
.github/workflows/markdown-linter.lock.ymlUpdates setup pin.
.github/workflows/malicious-code-scan.lock.ymlUpdates setup pin.
.github/workflows/link-checker.lock.ymlUpdates setup pin.
.github/workflows/glossary-maintainer.lock.ymlUpdates setup pin.
.github/workflows/efficiency-improver.lock.ymlUpdates setup pin.
.github/workflows/duplicate-code-detector.lock.ymlUpdates setup pin.
.github/workflows/dependabot-pr-bundler.lock.ymlUpdates setup pin.
.github/workflows/dependabot-issue-bundler.lock.ymlUpdates setup pin.
.github/workflows/daily-file-diet.lock.ymlUpdates setup pin.
.github/workflows/code-simplifier.lock.ymlUpdates setup pin.
.github/workflows/autofix.agent.lock.ymlUpdates setup pin.
.github/workflows/adhoc-qa.lock.ymlUpdates setup pin.
.github/workflows/address-review.agent.lock.ymlUpdates setup pin.
.github/workflows/add-tests.lock.ymlUpdates setup pin.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Evangelink
Amaury Levé (Evangelink) merged commit d52effb into mainAug 24, 2026
20 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dependabot/github_actions/github/gh-aw/actions/setup-0.86.2 branch August 24, 2026 08:21
Jakub Jareš (nohwnd) added a commit that referenced this pull request Aug 24, 2026
Conflict in .github/workflows/markdown-linter.lock.yml: #10657 bumped the
gh-aw setup pin from 435186c5 to 48e5fa3f across every lock file, while this
branch removed super-linter from the same header block.
Resolved by regenerating the lock file from its .md source with
`gh aw compile --action-mode release --action-tag 48e5fa3f` rather than editing
the generated file, so it picks up the new pin and keeps this branch's changes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesUpdates to dependency manifests.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

[main] Bump github/gh-aw/actions/setup from 0.86.0 to 0.86.2 - #10657

Merged
Amaury Levé (Evangelink) merged 1 commit into
mainfrom
dependabot/github_actions/github/gh-aw/actions/setup-0.86.2
Aug 24, 2026
Merged

[main] Bump github/gh-aw/actions/setup from 0.86.0 to 0.86.2#10657
Amaury Levé (Evangelink) merged 1 commit into
mainfrom
dependabot/github_actions/github/gh-aw/actions/setup-0.86.2

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 20, 2026

Copy link
Copy Markdown
Contributor

Bumps github/gh-aw/actions/setup from 0.86.0 to 0.86.2.

Release notes

Sourced from github/gh-aw/actions/setup's releases.

v0.86.2

🌟 Release Highlights

This release focuses on hardening the sandbox and MCP gateway, smoothing out safe-output and threat-detection reliability, and shipping a steady stream of security and quality fixes across the compiler and CLI.

✨ What's New

  • Docker sandbox (docker-sbx) rollout continues — the sandboxed execution environment now runs for a larger share of agentic workflows, with fixes for pre-flight step naming, gVisor false positives, and Docker Hub secret handling (#51264, #51294, #51341, #51439, #51949). See the sandbox reference.
  • Agent runtime trackingsandbox.agent.runtime is now stored in aw_info.json, and gh aw logs/gh aw audit gained a --runtime filter for easier debugging across engines (#51465, #52076). See agent runtimes.
  • MCP gateway hardening — explicit mount policy allowlisting for the safeoutputs backend server, plus a bump to gh-aw-mcpg v0.4.9 and github-mcp-server v1.9.0 (#51870, #51828).
  • Skills frontmatter flexibility — non-SHA refs are now allowed in skills frontmatter and pinned automatically at compile time, and an explicit end-marker syntax was added for inline skills/sub-agents (#51455, #51446).
  • Threat detection improvements — inline threat detection for Code Scanning Fixer, rendered detection logs with group/mask macros, and gh-aw's own <system> prompt block is no longer flagged as prompt injection (#51277, #51255, #51818). See threat detection.

🐛 Bug Fixes & Improvements

  • Fixed silent failures in the Copilot session data fetcher and in gh aw mcp inspect pagination (#51195, #51193).
  • Fixed Claude harness retrying invalid-JSON body errors with --continue instead of starting a fresh run (#51793).
  • Fixed a CGO/CJS workflow cache key collision that caused widespread job failures (#51342).
  • Fixed recurring gh-aw-firewall digest-pin loss on default firewall version bumps (#51423).
  • Fixed Windows MCP server timeouts by propagating context through GitHub CLI subprocess calls (#51426).
  • Fixed retry handling and denials in the Contribution Check proxy (#51631).
  • Added support for HEAD-only bundles when pushing to pull request branches (#51833).
  • Fixed safe-output run summary classification so entries are always linked and correctly attributed (#51484, #51478).

📚 Documentation

  • Documented the --runtime flag for gh aw logs/gh aw audit, agent runtime selection/troubleshooting, and clarified Claude engine selection in automated bootstrap (#52076, #51427, #52099).
  • Improved overall documentation discoverability and trimmed troubleshooting guides (#52065, #51251).

🔧 Internal

A large batch of custom-linter hardening, dependency bumps, test-parallelization, and dependency vulnerability remediations (container image pinning, ip-address patch, deprecated MCP container replacements) round out this release — thanks to the automated maintenance workflows keeping the codebase clean and secure.> Generated by 🚀 Release · auto · 20.7 AIC · ⊞ 11.3K


What's Changed

... (truncated)

Commits
  • 48e5fa3 Clarify Claude engine selection in automated bootstrap (#52099)
  • 9699516 Fix inverted strict: mode documentation in frontmatter reference (#52100)
  • fa5e232 Improve GitHub Agentic Workflows documentation discoverability (#52065)
  • 85f9048 Normalize report formatting in video-analyzer, plan, and centralization-drill...
  • 1dd49c6 Suppress benign workflow exfiltration findings (#52083)
  • c636d5f docs: document --runtime flag for gh aw logs and gh aw audit (#52076)
  • 62647ef Harden scanner/relaunch exec trust boundaries and argument validation (#52032)
  • 9922b2f Harden remote workflow import fallbacks to prevent cross-host downgrade to pu...
  • 81a1321 Remediate dynamic regexp pattern findings (#51941)
  • 485f970 [aw] Reduce Daily PR review tool-denial failures in Copilot SDK runs (#52060)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/gh-aw/actions/setup](https://github.com/github/gh-aw) from 0.86.0 to 0.86.2.
- [Release notes](https://github.com/github/gh-aw/releases)
- [Changelog](https://github.com/github/gh-aw/blob/main/CHANGELOG.md)
- [Commits](github/gh-aw@435186c...48e5fa3)
---
updated-dependencies:
- dependency-name: github/gh-aw/actions/setup
dependency-version: 0.86.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Updates to dependency manifests. github_actions labels Aug 20, 2026
CopilotAI balanced review requested due to automatic review settings August 20, 2026 06:40
@dependabotdependabotBot added dependencies Updates to dependency manifests. github_actions labels Aug 20, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the github/gh-aw/actions/setup pin from 0.86.0 to 0.86.2 across generated agentic workflows.

Changes:

  • Replaces executable setup-action references with the new immutable SHA.
  • Synchronizes generated action inventory comments.

Reviewed changes

Copilot reviewed 29 out of 29 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
.github/workflows/weekly-issue-activity.lock.ymlUpdates setup pin.
.github/workflows/unskip-closed-tests.lock.ymlUpdates setup pin.
.github/workflows/test-reviewer.agent.lock.ymlUpdates setup pin.
.github/workflows/test-reviewer-on-pr.agent.lock.ymlUpdates setup pin.
.github/workflows/test-improver.lock.ymlUpdates setup pin.
.github/workflows/sub-issue-closer.lock.ymlUpdates setup pin.
.github/workflows/review.agent.lock.ymlUpdates setup pin.
.github/workflows/review-on-open.agent.lock.ymlUpdates setup pin.
.github/workflows/review-after-autofix.agent.lock.ymlUpdates setup pin.
.github/workflows/repository-quality-improver.lock.ymlUpdates setup pin.
.github/workflows/pr-fix.lock.ymlUpdates setup pin.
.github/workflows/perf-improver.lock.ymlUpdates setup pin.
.github/workflows/parallel-safety-audit.lock.ymlUpdates setup pin.
.github/workflows/parallel-safety-audit-command.lock.ymlUpdates setup pin.
.github/workflows/msbuild-quality-review.lock.ymlUpdates setup pin.
.github/workflows/markdown-linter.lock.ymlUpdates setup pin.
.github/workflows/malicious-code-scan.lock.ymlUpdates setup pin.
.github/workflows/link-checker.lock.ymlUpdates setup pin.
.github/workflows/glossary-maintainer.lock.ymlUpdates setup pin.
.github/workflows/efficiency-improver.lock.ymlUpdates setup pin.
.github/workflows/duplicate-code-detector.lock.ymlUpdates setup pin.
.github/workflows/dependabot-pr-bundler.lock.ymlUpdates setup pin.
.github/workflows/dependabot-issue-bundler.lock.ymlUpdates setup pin.
.github/workflows/daily-file-diet.lock.ymlUpdates setup pin.
.github/workflows/code-simplifier.lock.ymlUpdates setup pin.
.github/workflows/autofix.agent.lock.ymlUpdates setup pin.
.github/workflows/adhoc-qa.lock.ymlUpdates setup pin.
.github/workflows/address-review.agent.lock.ymlUpdates setup pin.
.github/workflows/add-tests.lock.ymlUpdates setup pin.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Evangelink
Amaury Levé (Evangelink) merged commit d52effb into mainAug 24, 2026
20 checks passed
@Evangelink
Amaury Levé (Evangelink) deleted the dependabot/github_actions/github/gh-aw/actions/setup-0.86.2 branch August 24, 2026 08:21
Jakub Jareš (nohwnd) added a commit that referenced this pull request Aug 24, 2026
Conflict in .github/workflows/markdown-linter.lock.yml: #10657 bumped the
gh-aw setup pin from 435186c5 to 48e5fa3f across every lock file, while this
branch removed super-linter from the same header block.
Resolved by regenerating the lock file from its .md source with
`gh aw compile --action-mode release --action-tag 48e5fa3f` rather than editing
the generated file, so it picks up the new pin and keeps this branch's changes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesUpdates to dependency manifests.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Evangelink