microsoft/typespec

Public

mirrored from https://github.com/microsoft/typespecAvailable

CodeCommitsIssuesPull requestsActionsInsightsSecurity
6357dc0d0e1fb00a591a2a8aaf243804d727e52b

Branches

Tags

  • No tags available.
0Branches0Tags
Go to file
Add file
Code

Clone

HTTPS

Download ZIP

.github/workflows/bump-tcgc-csharp.lock.yml

1277lines · modecode

1# gh-aw-metadata: {"schema_version":"v3","frontmatter_hash":"42581920e1ea63400e4683852f9615ef8dbf7f3fc078f713081bd5e7afe3e77a","compiler_version":"v0.71.1","strict":true,"agent_id":"copilot"}
2# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_AGENT_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/checkout","sha":"de0fac2e4500dabe0009e67214ff5f5447ce83dd","version":"v6.0.2"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"239aec45b78c8799417efdd5bc6d8cc036629ec1","version":"v0.71.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.25.28","digest":"sha256:a8834e285807654bf680154faa710d43fe4365a0868142f5c20e48c85e137a7a","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.25.28@sha256:a8834e285807654bf680154faa710d43fe4365a0868142f5c20e48c85e137a7a"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.25.28","digest":"sha256:93290f2393752252911bd7c39a047f776c0b53063575e7bde4e304962a9a61cb","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.25.28@sha256:93290f2393752252911bd7c39a047f776c0b53063575e7bde4e304962a9a61cb"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.25.28","digest":"sha256:844c18280f82cd1b06345eb2f4e91966b34185bfc51c9f237c3e022e848fb474","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.25.28@sha256:844c18280f82cd1b06345eb2f4e91966b34185bfc51c9f237c3e022e848fb474"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.0"},{"image":"ghcr.io/github/github-mcp-server:v1.0.2"},{"image":"node:lts-alpine","digest":"sha256:d1b3b4da11eefd5941e7f0b9cf17783fc99d9c6fc34884a665f40a06dbdfc94f","pinned_image":"node:lts-alpine@sha256:d1b3b4da11eefd5941e7f0b9cf17783fc99d9c6fc34884a665f40a06dbdfc94f"}]}
3# ___ _ _
4# / _ \ | | (_)
5# | |_| | __ _ ___ _ __ | |_ _ ___
6# | _ |/ _` |/ _ \ '_ \| __| |/ __|
7# | | | | (_| | __/ | | | |_| | (__
8# \_| |_/\__, |\___|_| |_|\__|_|\___|
9# __/ |
10# _ _ |___/
11# | | | | / _| |
12# | | | | ___ _ __ _ __| |_| | _____ ____
13# | |/\| |/ _ \ '__| |/ /| _| |/ _ \ \ /\ / / ___|
14# \ /\ / (_) | | | | ( | | | | (_) \ V V /\__ \
15# \/ \/ \___/|_| |_|\_\|_| |_|\___/ \_/\_/ |___/
16#
17# This file was automatically generated by gh-aw (v0.71.1). DO NOT EDIT.
18#
19# To update this file, edit the corresponding .md file and run:
20# gh aw compile
21# Not all edits will cause changes to this file.
22#
23# For more information: https://github.github.com/gh-aw/introduction/overview/
24#
25# Daily TCGC version watcher for the http-client-csharp emitter. Checks the npm
26# registry for new non-dev releases of @azure-tools/typespec-client-generator-core
27# and, when a newer stable version is available and no equivalent issue already
28# exists, files a tracking issue assigned to GitHub Copilot to perform the upgrade.
29#
30# Secrets used:
31# - COPILOT_GITHUB_TOKEN
32# - GH_AW_AGENT_TOKEN
33# - GH_AW_GITHUB_MCP_SERVER_TOKEN
34# - GH_AW_GITHUB_TOKEN
35# - GITHUB_TOKEN
36#
37# Custom actions used:
38# - actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
39# - actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
40# - actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
41# - actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
42# - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
43# - github/gh-aw-actions/setup@239aec45b78c8799417efdd5bc6d8cc036629ec1 # v0.71.1
44#
45# Container images used:
46# - ghcr.io/github/gh-aw-firewall/agent:0.25.28@sha256:a8834e285807654bf680154faa710d43fe4365a0868142f5c20e48c85e137a7a
47# - ghcr.io/github/gh-aw-firewall/api-proxy:0.25.28@sha256:93290f2393752252911bd7c39a047f776c0b53063575e7bde4e304962a9a61cb
48# - ghcr.io/github/gh-aw-firewall/squid:0.25.28@sha256:844c18280f82cd1b06345eb2f4e91966b34185bfc51c9f237c3e022e848fb474
49# - ghcr.io/github/gh-aw-mcpg:v0.3.0
50# - ghcr.io/github/github-mcp-server:v1.0.2
51# - node:lts-alpine@sha256:d1b3b4da11eefd5941e7f0b9cf17783fc99d9c6fc34884a665f40a06dbdfc94f
52
53name: "Agentic TCGC Bump for http-client-csharp"
54"on":
55 schedule:
56 - cron: "13 3 * * *"
57 workflow_dispatch:
58 inputs:
59 aw_context:
60 default: ""
61 description: Agent caller context (used internally by Agentic Workflows).
62 required: false
63 type: string
64
65permissions: {}
66
67concurrency:
68 group: "gh-aw-${{ github.workflow }}"
69
70run-name: "Agentic TCGC Bump for http-client-csharp"
71
72jobs:
73 activation:
74 runs-on: ubuntu-slim
75 permissions:
76 actions: read
77 contents: read
78 outputs:
79 comment_id: ""
80 comment_repo: ""
81 engine_id: ${{ steps.generate_aw_info.outputs.engine_id }}
82 lockdown_check_failed: ${{ steps.generate_aw_info.outputs.lockdown_check_failed == 'true' }}
83 model: ${{ steps.generate_aw_info.outputs.model }}
84 secret_verification_result: ${{ steps.validate-secret.outputs.verification_result }}
85 setup-trace-id: ${{ steps.setup.outputs.trace-id }}
86 stale_lock_file_failed: ${{ steps.check-lock-file.outputs.stale_lock_file_failed == 'true' }}
87 steps:
88 - name: Setup Scripts
89 id: setup
90 uses: github/gh-aw-actions/setup@239aec45b78c8799417efdd5bc6d8cc036629ec1 # v0.71.1
91 with:
92 destination: ${{ runner.temp }}/gh-aw/actions
93 job-name: ${{ github.job }}
94 - name: Generate agentic run info
95 id: generate_aw_info
96 env:
97 GH_AW_INFO_ENGINE_ID: "copilot"
98 GH_AW_INFO_ENGINE_NAME: "GitHub Copilot CLI"
99 GH_AW_INFO_MODEL: ${{ vars.GH_AW_MODEL_AGENT_COPILOT || 'auto' }}
100 GH_AW_INFO_VERSION: "1.0.35"
101 GH_AW_INFO_AGENT_VERSION: "1.0.35"
102 GH_AW_INFO_CLI_VERSION: "v0.71.1"
103 GH_AW_INFO_WORKFLOW_NAME: "Agentic TCGC Bump for http-client-csharp"
104 GH_AW_INFO_EXPERIMENTAL: "false"
105 GH_AW_INFO_SUPPORTS_TOOLS_ALLOWLIST: "true"
106 GH_AW_INFO_STAGED: "false"
107 GH_AW_INFO_ALLOWED_DOMAINS: '["defaults"]'
108 GH_AW_INFO_FIREWALL_ENABLED: "true"
109 GH_AW_INFO_AWF_VERSION: "v0.25.28"
110 GH_AW_INFO_AWMG_VERSION: ""
111 GH_AW_INFO_FIREWALL_TYPE: "squid"
112 GH_AW_COMPILED_STRICT: "true"
113 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
114 with:
115 script: |
116 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
117 setupGlobals(core, github, context, exec, io, getOctokit);
118 const { main } = require('${{ runner.temp }}/gh-aw/actions/generate_aw_info.cjs');
119 await main(core, context);
120 - name: Validate COPILOT_GITHUB_TOKEN secret
121 id: validate-secret
122 run: bash "${RUNNER_TEMP}/gh-aw/actions/validate_multi_secret.sh" COPILOT_GITHUB_TOKEN 'GitHub Copilot CLI' https://github.github.com/gh-aw/reference/engines/#github-copilot-default
123 env:
124 COPILOT_GITHUB_TOKEN: ${{ secrets.COPILOT_GITHUB_TOKEN }}
125 - name: Checkout .github and .agents folders
126 uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
127 with:
128 persist-credentials: false
129 sparse-checkout: |
130 .github
131 .agents
132 .claude
133 .codex
134 .crush
135 .gemini
136 .opencode
137 sparse-checkout-cone-mode: true
138 fetch-depth: 1
139 - name: Save agent config folders for base branch restoration
140 env:
141 GH_AW_AGENT_FOLDERS: ".agents .claude .codex .crush .gemini .github .opencode"
142 GH_AW_AGENT_FILES: ".crush.json AGENTS.md CLAUDE.md GEMINI.md opencode.jsonc"
143 # poutine:ignore untrusted_checkout_exec
144 run: bash "${RUNNER_TEMP}/gh-aw/actions/save_base_github_folders.sh"
145 - name: Check workflow lock file
146 id: check-lock-file
147 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
148 env:
149 GH_AW_WORKFLOW_FILE: "bump-tcgc-csharp.lock.yml"
150 GH_AW_CONTEXT_WORKFLOW_REF: "${{ github.workflow_ref }}"
151 with:
152 script: |
153 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
154 setupGlobals(core, github, context, exec, io, getOctokit);
155 const { main } = require('${{ runner.temp }}/gh-aw/actions/check_workflow_timestamp_api.cjs');
156 await main();
157 - name: Check compile-agentic version
158 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
159 env:
160 GH_AW_COMPILED_VERSION: "v0.71.1"
161 with:
162 script: |
163 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
164 setupGlobals(core, github, context, exec, io, getOctokit);
165 const { main } = require('${{ runner.temp }}/gh-aw/actions/check_version_updates.cjs');
166 await main();
167 - name: Create prompt with built-in context
168 env:
169 GH_AW_PROMPT: /tmp/gh-aw/aw-prompts/prompt.txt
170 GH_AW_SAFE_OUTPUTS: ${{ runner.temp }}/gh-aw/safeoutputs/outputs.jsonl
171 GH_AW_GITHUB_ACTOR: ${{ github.actor }}
172 GH_AW_GITHUB_EVENT_COMMENT_ID: ${{ github.event.comment.id }}
173 GH_AW_GITHUB_EVENT_DISCUSSION_NUMBER: ${{ github.event.discussion.number }}
174 GH_AW_GITHUB_EVENT_ISSUE_NUMBER: ${{ github.event.issue.number }}
175 GH_AW_GITHUB_EVENT_PULL_REQUEST_NUMBER: ${{ github.event.pull_request.number }}
176 GH_AW_GITHUB_REPOSITORY: ${{ github.repository }}
177 GH_AW_GITHUB_RUN_ID: ${{ github.run_id }}
178 GH_AW_GITHUB_WORKSPACE: ${{ github.workspace }}
179 # poutine:ignore untrusted_checkout_exec
180 run: |
181 bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh"
182 {
183 cat << 'GH_AW_PROMPT_b18ec21f7f4d20ce_EOF'
184 <system>
185 GH_AW_PROMPT_b18ec21f7f4d20ce_EOF
186 cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md"
187 cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md"
188 cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md"
189 cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md"
190 cat << 'GH_AW_PROMPT_b18ec21f7f4d20ce_EOF'
191 <safe-output-tools>
192 Tools: create_issue, assign_to_agent, missing_tool, missing_data, noop
193 </safe-output-tools>
194 <github-context>
195 The following GitHub context information is available for this workflow:
196 {{#if __GH_AW_GITHUB_ACTOR__ }}
197 - **actor**: __GH_AW_GITHUB_ACTOR__
198 {{/if}}
199 {{#if __GH_AW_GITHUB_REPOSITORY__ }}
200 - **repository**: __GH_AW_GITHUB_REPOSITORY__
201 {{/if}}
202 {{#if __GH_AW_GITHUB_WORKSPACE__ }}
203 - **workspace**: __GH_AW_GITHUB_WORKSPACE__
204 {{/if}}
205 {{#if __GH_AW_GITHUB_EVENT_ISSUE_NUMBER__ }}
206 - **issue-number**: #__GH_AW_GITHUB_EVENT_ISSUE_NUMBER__
207 {{/if}}
208 {{#if __GH_AW_GITHUB_EVENT_DISCUSSION_NUMBER__ }}
209 - **discussion-number**: #__GH_AW_GITHUB_EVENT_DISCUSSION_NUMBER__
210 {{/if}}
211 {{#if __GH_AW_GITHUB_EVENT_PULL_REQUEST_NUMBER__ }}
212 - **pull-request-number**: #__GH_AW_GITHUB_EVENT_PULL_REQUEST_NUMBER__
213 {{/if}}
214 {{#if __GH_AW_GITHUB_EVENT_COMMENT_ID__ }}
215 - **comment-id**: __GH_AW_GITHUB_EVENT_COMMENT_ID__
216 {{/if}}
217 {{#if __GH_AW_GITHUB_RUN_ID__ }}
218 - **workflow-run-id**: __GH_AW_GITHUB_RUN_ID__
219 {{/if}}
220 </github-context>
221
222 GH_AW_PROMPT_b18ec21f7f4d20ce_EOF
223 cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md"
224 cat << 'GH_AW_PROMPT_b18ec21f7f4d20ce_EOF'
225 </system>
226 {{#runtime-import .github/workflows/bump-tcgc-csharp.md}}
227 GH_AW_PROMPT_b18ec21f7f4d20ce_EOF
228 } > "$GH_AW_PROMPT"
229 - name: Interpolate variables and render templates
230 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
231 env:
232 GH_AW_PROMPT: /tmp/gh-aw/aw-prompts/prompt.txt
233 GH_AW_GITHUB_REPOSITORY: ${{ github.repository }}
234 with:
235 script: |
236 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
237 setupGlobals(core, github, context, exec, io, getOctokit);
238 const { main } = require('${{ runner.temp }}/gh-aw/actions/interpolate_prompt.cjs');
239 await main();
240 - name: Substitute placeholders
241 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
242 env:
243 GH_AW_PROMPT: /tmp/gh-aw/aw-prompts/prompt.txt
244 GH_AW_GITHUB_ACTOR: ${{ github.actor }}
245 GH_AW_GITHUB_EVENT_COMMENT_ID: ${{ github.event.comment.id }}
246 GH_AW_GITHUB_EVENT_DISCUSSION_NUMBER: ${{ github.event.discussion.number }}
247 GH_AW_GITHUB_EVENT_ISSUE_NUMBER: ${{ github.event.issue.number }}
248 GH_AW_GITHUB_EVENT_PULL_REQUEST_NUMBER: ${{ github.event.pull_request.number }}
249 GH_AW_GITHUB_REPOSITORY: ${{ github.repository }}
250 GH_AW_GITHUB_RUN_ID: ${{ github.run_id }}
251 GH_AW_GITHUB_WORKSPACE: ${{ github.workspace }}
252 with:
253 script: |
254 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
255 setupGlobals(core, github, context, exec, io, getOctokit);
256
257 const substitutePlaceholders = require('${{ runner.temp }}/gh-aw/actions/substitute_placeholders.cjs');
258
259 // Call the substitution function
260 return await substitutePlaceholders({
261 file: process.env.GH_AW_PROMPT,
262 substitutions: {
263 GH_AW_GITHUB_ACTOR: process.env.GH_AW_GITHUB_ACTOR,
264 GH_AW_GITHUB_EVENT_COMMENT_ID: process.env.GH_AW_GITHUB_EVENT_COMMENT_ID,
265 GH_AW_GITHUB_EVENT_DISCUSSION_NUMBER: process.env.GH_AW_GITHUB_EVENT_DISCUSSION_NUMBER,
266 GH_AW_GITHUB_EVENT_ISSUE_NUMBER: process.env.GH_AW_GITHUB_EVENT_ISSUE_NUMBER,
267 GH_AW_GITHUB_EVENT_PULL_REQUEST_NUMBER: process.env.GH_AW_GITHUB_EVENT_PULL_REQUEST_NUMBER,
268 GH_AW_GITHUB_REPOSITORY: process.env.GH_AW_GITHUB_REPOSITORY,
269 GH_AW_GITHUB_RUN_ID: process.env.GH_AW_GITHUB_RUN_ID,
270 GH_AW_GITHUB_WORKSPACE: process.env.GH_AW_GITHUB_WORKSPACE
271 }
272 });
273 - name: Validate prompt placeholders
274 env:
275 GH_AW_PROMPT: /tmp/gh-aw/aw-prompts/prompt.txt
276 # poutine:ignore untrusted_checkout_exec
277 run: bash "${RUNNER_TEMP}/gh-aw/actions/validate_prompt_placeholders.sh"
278 - name: Print prompt
279 env:
280 GH_AW_PROMPT: /tmp/gh-aw/aw-prompts/prompt.txt
281 # poutine:ignore untrusted_checkout_exec
282 run: bash "${RUNNER_TEMP}/gh-aw/actions/print_prompt_summary.sh"
283 - name: Upload activation artifact
284 if: success()
285 uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
286 with:
287 name: activation
288 path: |
289 /tmp/gh-aw/aw_info.json
290 /tmp/gh-aw/aw-prompts/prompt.txt
291 /tmp/gh-aw/github_rate_limits.jsonl
292 /tmp/gh-aw/base
293 if-no-files-found: ignore
294 retention-days: 1
295
296 agent:
297 needs: activation
298 runs-on: ubuntu-latest
299 permissions: read-all
300 concurrency:
301 group: "gh-aw-copilot-${{ github.workflow }}"
302 env:
303 DEFAULT_BRANCH: ${{ github.event.repository.default_branch }}
304 GH_AW_ASSETS_ALLOWED_EXTS: ""
305 GH_AW_ASSETS_BRANCH: ""
306 GH_AW_ASSETS_MAX_SIZE_KB: 0
307 GH_AW_MCP_LOG_DIR: /tmp/gh-aw/mcp-logs/safeoutputs
308 GH_AW_WORKFLOW_ID_SANITIZED: bumptcgccsharp
309 outputs:
310 agentic_engine_timeout: ${{ steps.detect-copilot-errors.outputs.agentic_engine_timeout || 'false' }}
311 checkout_pr_success: ${{ steps.checkout-pr.outputs.checkout_pr_success || 'true' }}
312 effective_tokens: ${{ steps.parse-mcp-gateway.outputs.effective_tokens }}
313 has_patch: ${{ steps.collect_output.outputs.has_patch }}
314 inference_access_error: ${{ steps.detect-copilot-errors.outputs.inference_access_error || 'false' }}
315 mcp_policy_error: ${{ steps.detect-copilot-errors.outputs.mcp_policy_error || 'false' }}
316 model: ${{ needs.activation.outputs.model }}
317 model_not_supported_error: ${{ steps.detect-copilot-errors.outputs.model_not_supported_error || 'false' }}
318 output: ${{ steps.collect_output.outputs.output }}
319 output_types: ${{ steps.collect_output.outputs.output_types }}
320 setup-trace-id: ${{ steps.setup.outputs.trace-id }}
321 steps:
322 - name: Setup Scripts
323 id: setup
324 uses: github/gh-aw-actions/setup@239aec45b78c8799417efdd5bc6d8cc036629ec1 # v0.71.1
325 with:
326 destination: ${{ runner.temp }}/gh-aw/actions
327 job-name: ${{ github.job }}
328 trace-id: ${{ needs.activation.outputs.setup-trace-id }}
329 - name: Set runtime paths
330 id: set-runtime-paths
331 run: |
332 {
333 echo "GH_AW_SAFE_OUTPUTS=${RUNNER_TEMP}/gh-aw/safeoutputs/outputs.jsonl"
334 echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json"
335 echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json"
336 } >> "$GITHUB_OUTPUT"
337 - name: Checkout repository
338 uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
339 with:
340 persist-credentials: false
341 - name: Create gh-aw temp directory
342 run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh"
343 - name: Configure gh CLI for GitHub Enterprise
344 run: bash "${RUNNER_TEMP}/gh-aw/actions/configure_gh_for_ghe.sh"
345 env:
346 GH_TOKEN: ${{ github.token }}
347 - name: Configure Git credentials
348 env:
349 REPO_NAME: ${{ github.repository }}
350 SERVER_URL: ${{ github.server_url }}
351 GITHUB_TOKEN: ${{ github.token }}
352 run: |
353 git config --global user.email "github-actions[bot]@users.noreply.github.com"
354 git config --global user.name "github-actions[bot]"
355 git config --global am.keepcr true
356 # Re-authenticate git with GitHub token
357 SERVER_URL_STRIPPED="${SERVER_URL#https://}"
358 git remote set-url origin "https://x-access-token:${GITHUB_TOKEN}@${SERVER_URL_STRIPPED}/${REPO_NAME}.git"
359 echo "Git configured with standard GitHub Actions identity"
360 - name: Checkout PR branch
361 id: checkout-pr
362 if: |
363 github.event.pull_request || github.event.issue.pull_request
364 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
365 env:
366 GH_TOKEN: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}
367 with:
368 github-token: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}
369 script: |
370 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
371 setupGlobals(core, github, context, exec, io, getOctokit);
372 const { main } = require('${{ runner.temp }}/gh-aw/actions/checkout_pr_branch.cjs');
373 await main();
374 - name: Install GitHub Copilot CLI
375 run: bash "${RUNNER_TEMP}/gh-aw/actions/install_copilot_cli.sh" 1.0.35
376 env:
377 GH_HOST: github.com
378 - name: Install AWF binary
379 run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.25.28
380 - name: Determine automatic lockdown mode for GitHub MCP Server
381 id: determine-automatic-lockdown
382 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
383 env:
384 GH_AW_GITHUB_TOKEN: ${{ secrets.GH_AW_GITHUB_TOKEN }}
385 GH_AW_GITHUB_MCP_SERVER_TOKEN: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN }}
386 with:
387 script: |
388 const determineAutomaticLockdown = require('${{ runner.temp }}/gh-aw/actions/determine_automatic_lockdown.cjs');
389 await determineAutomaticLockdown(github, context, core);
390 - name: Download activation artifact
391 uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
392 with:
393 name: activation
394 path: /tmp/gh-aw
395 - name: Restore agent config folders from base branch
396 if: steps.checkout-pr.outcome == 'success'
397 env:
398 GH_AW_AGENT_FOLDERS: ".agents .claude .codex .crush .gemini .github .opencode"
399 GH_AW_AGENT_FILES: ".crush.json AGENTS.md CLAUDE.md GEMINI.md opencode.jsonc"
400 run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_base_github_folders.sh"
401 - name: Download container images
402 run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.25.28@sha256:a8834e285807654bf680154faa710d43fe4365a0868142f5c20e48c85e137a7a ghcr.io/github/gh-aw-firewall/api-proxy:0.25.28@sha256:93290f2393752252911bd7c39a047f776c0b53063575e7bde4e304962a9a61cb ghcr.io/github/gh-aw-firewall/squid:0.25.28@sha256:844c18280f82cd1b06345eb2f4e91966b34185bfc51c9f237c3e022e848fb474 ghcr.io/github/gh-aw-mcpg:v0.3.0 ghcr.io/github/github-mcp-server:v1.0.2 node:lts-alpine@sha256:d1b3b4da11eefd5941e7f0b9cf17783fc99d9c6fc34884a665f40a06dbdfc94f
403 - name: Write Safe Outputs Config
404 run: |
405 mkdir -p "${RUNNER_TEMP}/gh-aw/safeoutputs"
406 mkdir -p /tmp/gh-aw/safeoutputs
407 mkdir -p /tmp/gh-aw/mcp-logs/safeoutputs
408 cat > "${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" << 'GH_AW_SAFE_OUTPUTS_CONFIG_d87a86e14a78953f_EOF'
409 {"assign_to_agent":{"max":1,"model":"claude-opus-4.6","name":"copilot"},"create_issue":{"assignees":["copilot"],"labels":["emitter:client:csharp"],"max":1,"title_prefix":"Bump TCGC to "},"create_report_incomplete_issue":{},"missing_data":{},"missing_tool":{},"noop":{"max":1,"report-as-issue":"false"},"report_incomplete":{}}
410 GH_AW_SAFE_OUTPUTS_CONFIG_d87a86e14a78953f_EOF
411 - name: Write Safe Outputs Tools
412 env:
413 GH_AW_TOOLS_META_JSON: |
414 {
415 "description_suffixes": {
416 "assign_to_agent": " CONSTRAINTS: Maximum 1 issue(s) can be assigned to agent.",
417 "create_issue": " CONSTRAINTS: Maximum 1 issue(s) can be created. Title will be prefixed with \"Bump TCGC to \". Labels [\"emitter:client:csharp\"] will be automatically added. Assignees [\"copilot\"] will be automatically assigned."
418 },
419 "repo_params": {},
420 "dynamic_tools": []
421 }
422 GH_AW_VALIDATION_JSON: |
423 {
424 "assign_to_agent": {
425 "defaultMax": 1,
426 "fields": {
427 "agent": {
428 "type": "string",
429 "sanitize": true,
430 "maxLength": 128
431 },
432 "issue_number": {
433 "issueNumberOrTemporaryId": true
434 },
435 "pull_number": {
436 "optionalPositiveInteger": true
437 },
438 "pull_request_repo": {
439 "type": "string",
440 "maxLength": 256
441 },
442 "repo": {
443 "type": "string",
444 "maxLength": 256
445 }
446 },
447 "customValidation": "requiresOneOf:issue_number,pull_number"
448 },
449 "create_issue": {
450 "defaultMax": 1,
451 "fields": {
452 "body": {
453 "required": true,
454 "type": "string",
455 "sanitize": true,
456 "maxLength": 65000
457 },
458 "labels": {
459 "type": "array",
460 "itemType": "string",
461 "itemSanitize": true,
462 "itemMaxLength": 128
463 },
464 "parent": {
465 "issueOrPRNumber": true
466 },
467 "repo": {
468 "type": "string",
469 "maxLength": 256
470 },
471 "temporary_id": {
472 "type": "string"
473 },
474 "title": {
475 "required": true,
476 "type": "string",
477 "sanitize": true,
478 "maxLength": 128
479 }
480 }
481 },
482 "missing_data": {
483 "defaultMax": 20,
484 "fields": {
485 "alternatives": {
486 "type": "string",
487 "sanitize": true,
488 "maxLength": 256
489 },
490 "context": {
491 "type": "string",
492 "sanitize": true,
493 "maxLength": 256
494 },
495 "data_type": {
496 "type": "string",
497 "sanitize": true,
498 "maxLength": 128
499 },
500 "reason": {
501 "type": "string",
502 "sanitize": true,
503 "maxLength": 256
504 }
505 }
506 },
507 "missing_tool": {
508 "defaultMax": 20,
509 "fields": {
510 "alternatives": {
511 "type": "string",
512 "sanitize": true,
513 "maxLength": 512
514 },
515 "reason": {
516 "required": true,
517 "type": "string",
518 "sanitize": true,
519 "maxLength": 256
520 },
521 "tool": {
522 "type": "string",
523 "sanitize": true,
524 "maxLength": 128
525 }
526 }
527 },
528 "noop": {
529 "defaultMax": 1,
530 "fields": {
531 "message": {
532 "required": true,
533 "type": "string",
534 "sanitize": true,
535 "maxLength": 65000
536 }
537 }
538 },
539 "report_incomplete": {
540 "defaultMax": 5,
541 "fields": {
542 "details": {
543 "type": "string",
544 "sanitize": true,
545 "maxLength": 65000
546 },
547 "reason": {
548 "required": true,
549 "type": "string",
550 "sanitize": true,
551 "maxLength": 1024
552 }
553 }
554 }
555 }
556 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
557 with:
558 script: |
559 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
560 setupGlobals(core, github, context, exec, io, getOctokit);
561 const { main } = require('${{ runner.temp }}/gh-aw/actions/generate_safe_outputs_tools.cjs');
562 await main();
563 - name: Generate Safe Outputs MCP Server Config
564 id: safe-outputs-config
565 run: |
566 # Generate a secure random API key (360 bits of entropy, 40+ chars)
567 # Mask immediately to prevent timing vulnerabilities
568 API_KEY=$(openssl rand -base64 45 | tr -d '/+=')
569 echo "::add-mask::${API_KEY}"
570
571 PORT=3001
572
573 # Set outputs for next steps
574 {
575 echo "safe_outputs_api_key=${API_KEY}"
576 echo "safe_outputs_port=${PORT}"
577 } >> "$GITHUB_OUTPUT"
578
579 echo "Safe Outputs MCP server will run on port ${PORT}"
580
581 - name: Start Safe Outputs MCP HTTP Server
582 id: safe-outputs-start
583 env:
584 DEBUG: '*'
585 GH_AW_SAFE_OUTPUTS: ${{ steps.set-runtime-paths.outputs.GH_AW_SAFE_OUTPUTS }}
586 GH_AW_SAFE_OUTPUTS_PORT: ${{ steps.safe-outputs-config.outputs.safe_outputs_port }}
587 GH_AW_SAFE_OUTPUTS_API_KEY: ${{ steps.safe-outputs-config.outputs.safe_outputs_api_key }}
588 GH_AW_SAFE_OUTPUTS_TOOLS_PATH: ${{ runner.temp }}/gh-aw/safeoutputs/tools.json
589 GH_AW_SAFE_OUTPUTS_CONFIG_PATH: ${{ runner.temp }}/gh-aw/safeoutputs/config.json
590 GH_AW_MCP_LOG_DIR: /tmp/gh-aw/mcp-logs/safeoutputs
591 run: |
592 # Environment variables are set above to prevent template injection
593 export DEBUG
594 export GH_AW_SAFE_OUTPUTS
595 export GH_AW_SAFE_OUTPUTS_PORT
596 export GH_AW_SAFE_OUTPUTS_API_KEY
597 export GH_AW_SAFE_OUTPUTS_TOOLS_PATH
598 export GH_AW_SAFE_OUTPUTS_CONFIG_PATH
599 export GH_AW_MCP_LOG_DIR
600
601 bash "${RUNNER_TEMP}/gh-aw/actions/start_safe_outputs_server.sh"
602
603 - name: Start MCP Gateway
604 id: start-mcp-gateway
605 env:
606 GH_AW_SAFE_OUTPUTS: ${{ steps.set-runtime-paths.outputs.GH_AW_SAFE_OUTPUTS }}
607 GH_AW_SAFE_OUTPUTS_API_KEY: ${{ steps.safe-outputs-start.outputs.api_key }}
608 GH_AW_SAFE_OUTPUTS_PORT: ${{ steps.safe-outputs-start.outputs.port }}
609 GITHUB_MCP_GUARD_MIN_INTEGRITY: ${{ steps.determine-automatic-lockdown.outputs.min_integrity }}
610 GITHUB_MCP_GUARD_REPOS: ${{ steps.determine-automatic-lockdown.outputs.repos }}
611 GITHUB_MCP_SERVER_TOKEN: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}
612 run: |
613 set -eo pipefail
614 mkdir -p "${RUNNER_TEMP}/gh-aw/mcp-config"
615
616 # Export gateway environment variables for MCP config and gateway script
617 export MCP_GATEWAY_PORT="8080"
618 export MCP_GATEWAY_DOMAIN="host.docker.internal"
619 MCP_GATEWAY_API_KEY=$(openssl rand -base64 45 | tr -d '/+=')
620 echo "::add-mask::${MCP_GATEWAY_API_KEY}"
621 export MCP_GATEWAY_API_KEY
622 export MCP_GATEWAY_PAYLOAD_DIR="/tmp/gh-aw/mcp-payloads"
623 mkdir -p "${MCP_GATEWAY_PAYLOAD_DIR}"
624 export MCP_GATEWAY_PAYLOAD_SIZE_THRESHOLD="524288"
625 export DEBUG="*"
626
627 export GH_AW_ENGINE="copilot"
628 MCP_GATEWAY_UID=$(id -u 2>/dev/null || echo '0')
629 MCP_GATEWAY_GID=$(id -g 2>/dev/null || echo '0')
630 DOCKER_SOCK_GID=$(stat -c '%g' /var/run/docker.sock 2>/dev/null || echo '0')
631 export MCP_GATEWAY_DOCKER_COMMAND='docker run -i --rm --network host --add-host host.docker.internal:127.0.0.1 --user '"${MCP_GATEWAY_UID}"':'"${MCP_GATEWAY_GID}"' --group-add '"${DOCKER_SOCK_GID}"' -v /var/run/docker.sock:/var/run/docker.sock -e MCP_GATEWAY_PORT -e MCP_GATEWAY_DOMAIN -e MCP_GATEWAY_API_KEY -e MCP_GATEWAY_PAYLOAD_DIR -e MCP_GATEWAY_PAYLOAD_SIZE_THRESHOLD -e DEBUG -e MCP_GATEWAY_LOG_DIR -e GH_AW_MCP_LOG_DIR -e GH_AW_SAFE_OUTPUTS -e GH_AW_SAFE_OUTPUTS_CONFIG_PATH -e GH_AW_SAFE_OUTPUTS_TOOLS_PATH -e GH_AW_ASSETS_BRANCH -e GH_AW_ASSETS_MAX_SIZE_KB -e GH_AW_ASSETS_ALLOWED_EXTS -e DEFAULT_BRANCH -e GITHUB_MCP_SERVER_TOKEN -e GITHUB_MCP_GUARD_MIN_INTEGRITY -e GITHUB_MCP_GUARD_REPOS -e GITHUB_REPOSITORY -e GITHUB_SERVER_URL -e GITHUB_SHA -e GITHUB_WORKSPACE -e GITHUB_TOKEN -e GITHUB_RUN_ID -e GITHUB_RUN_NUMBER -e GITHUB_RUN_ATTEMPT -e GITHUB_JOB -e GITHUB_ACTION -e GITHUB_EVENT_NAME -e GITHUB_EVENT_PATH -e GITHUB_ACTOR -e GITHUB_ACTOR_ID -e GITHUB_TRIGGERING_ACTOR -e GITHUB_WORKFLOW -e GITHUB_WORKFLOW_REF -e GITHUB_WORKFLOW_SHA -e GITHUB_REF -e GITHUB_REF_NAME -e GITHUB_REF_TYPE -e GITHUB_HEAD_REF -e GITHUB_BASE_REF -e GH_AW_SAFE_OUTPUTS_PORT -e GH_AW_SAFE_OUTPUTS_API_KEY -v /tmp/gh-aw/mcp-payloads:/tmp/gh-aw/mcp-payloads:rw -v /opt:/opt:ro -v /tmp:/tmp:rw -v '"${GITHUB_WORKSPACE}"':'"${GITHUB_WORKSPACE}"':rw ghcr.io/github/gh-aw-mcpg:v0.3.0'
632
633 mkdir -p /home/runner/.copilot
634 GH_AW_NODE=$(which node 2>/dev/null || command -v node 2>/dev/null || echo node)
635 cat << GH_AW_MCP_CONFIG_95be42a62439f3dc_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs"
636 {
637 "mcpServers": {
638 "github": {
639 "type": "stdio",
640 "container": "ghcr.io/github/github-mcp-server:v1.0.2",
641 "env": {
642 "GITHUB_HOST": "\${GITHUB_SERVER_URL}",
643 "GITHUB_PERSONAL_ACCESS_TOKEN": "\${GITHUB_MCP_SERVER_TOKEN}",
644 "GITHUB_READ_ONLY": "1",
645 "GITHUB_TOOLSETS": "issues,repos"
646 },
647 "guard-policies": {
648 "allow-only": {
649 "min-integrity": "$GITHUB_MCP_GUARD_MIN_INTEGRITY",
650 "repos": "$GITHUB_MCP_GUARD_REPOS"
651 }
652 }
653 },
654 "safeoutputs": {
655 "type": "http",
656 "url": "http://host.docker.internal:$GH_AW_SAFE_OUTPUTS_PORT",
657 "headers": {
658 "Authorization": "\${GH_AW_SAFE_OUTPUTS_API_KEY}"
659 },
660 "guard-policies": {
661 "write-sink": {
662 "accept": [
663 "*"
664 ]
665 }
666 }
667 }
668 },
669 "gateway": {
670 "port": $MCP_GATEWAY_PORT,
671 "domain": "${MCP_GATEWAY_DOMAIN}",
672 "apiKey": "${MCP_GATEWAY_API_KEY}",
673 "payloadDir": "${MCP_GATEWAY_PAYLOAD_DIR}"
674 }
675 }
676 GH_AW_MCP_CONFIG_95be42a62439f3dc_EOF
677 - name: Clean git credentials
678 continue-on-error: true
679 run: bash "${RUNNER_TEMP}/gh-aw/actions/clean_git_credentials.sh"
680 - name: Execute GitHub Copilot CLI
681 id: agentic_execution
682 # Copilot CLI tool arguments (sorted):
683 timeout-minutes: 15
684 run: |
685 set -o pipefail
686 touch /tmp/gh-aw/agent-step-summary.md
687 GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true)
688 export GH_AW_NODE_BIN
689 (umask 177 && touch /tmp/gh-aw/agent-stdio.log)
690 # shellcheck disable=SC1003
691 sudo -E awf --container-workdir "${GITHUB_WORKSPACE}" --mount "${RUNNER_TEMP}/gh-aw:${RUNNER_TEMP}/gh-aw:ro" --mount "${RUNNER_TEMP}/gh-aw:/host${RUNNER_TEMP}/gh-aw:ro" --env-all --exclude-env COPILOT_GITHUB_TOKEN --exclude-env GITHUB_MCP_SERVER_TOKEN --exclude-env MCP_GATEWAY_API_KEY --allow-domains api.business.githubcopilot.com,api.enterprise.githubcopilot.com,api.github.com,api.githubcopilot.com,api.individual.githubcopilot.com,api.snapcraft.io,archive.ubuntu.com,azure.archive.ubuntu.com,crl.geotrust.com,crl.globalsign.com,crl.identrust.com,crl.sectigo.com,crl.thawte.com,crl.usertrust.com,crl.verisign.com,crl3.digicert.com,crl4.digicert.com,crls.ssl.com,github.com,host.docker.internal,json-schema.org,json.schemastore.org,keyserver.ubuntu.com,ocsp.digicert.com,ocsp.geotrust.com,ocsp.globalsign.com,ocsp.identrust.com,ocsp.sectigo.com,ocsp.ssl.com,ocsp.thawte.com,ocsp.usertrust.com,ocsp.verisign.com,packagecloud.io,packages.cloud.google.com,packages.microsoft.com,ppa.launchpad.net,raw.githubusercontent.com,registry.npmjs.org,s.symcb.com,s.symcd.com,security.ubuntu.com,telemetry.enterprise.githubcopilot.com,ts-crl.ws.symantec.com,ts-ocsp.ws.symantec.com,www.googleapis.com --log-level info --proxy-logs-dir /tmp/gh-aw/sandbox/firewall/logs --audit-dir /tmp/gh-aw/sandbox/firewall/audit --enable-host-access --allow-host-ports 80,443,8080 --image-tag 0.25.28,squid=sha256:844c18280f82cd1b06345eb2f4e91966b34185bfc51c9f237c3e022e848fb474,agent=sha256:a8834e285807654bf680154faa710d43fe4365a0868142f5c20e48c85e137a7a,api-proxy=sha256:93290f2393752252911bd7c39a047f776c0b53063575e7bde4e304962a9a61cb,cli-proxy=sha256:fdf310e4678ce58d248c466b89399e9680a3003038fd19322c388559016aaac7 --skip-pull --enable-api-proxy \
692 -- /bin/bash -c 'GH_AW_NODE_EXEC="${GH_AW_NODE_BIN:-}"; if [ -z "$GH_AW_NODE_EXEC" ] || [ ! -x "$GH_AW_NODE_EXEC" ]; then GH_AW_NODE_EXEC="$(command -v node 2>/dev/null || echo node)"; fi; "$GH_AW_NODE_EXEC" ${RUNNER_TEMP}/gh-aw/actions/copilot_driver.cjs /usr/local/bin/copilot --add-dir /tmp/gh-aw/ --log-level all --log-dir /tmp/gh-aw/sandbox/agent/logs/ --disable-builtin-mcps --no-ask-user --allow-all-tools --allow-all-paths --add-dir "${GITHUB_WORKSPACE}" --prompt-file /tmp/gh-aw/aw-prompts/prompt.txt' 2>&1 | tee -a /tmp/gh-aw/agent-stdio.log
693 env:
694 COPILOT_AGENT_RUNNER_TYPE: STANDALONE
695 COPILOT_API_KEY: dummy-byok-key-for-offline-mode
696 COPILOT_GITHUB_TOKEN: ${{ secrets.COPILOT_GITHUB_TOKEN }}
697 COPILOT_MODEL: ${{ vars.GH_AW_MODEL_AGENT_COPILOT || 'claude-sonnet-4.6' }}
698 GH_AW_MCP_CONFIG: /home/runner/.copilot/mcp-config.json
699 GH_AW_PHASE: agent
700 GH_AW_PROMPT: /tmp/gh-aw/aw-prompts/prompt.txt
701 GH_AW_SAFE_OUTPUTS: ${{ steps.set-runtime-paths.outputs.GH_AW_SAFE_OUTPUTS }}
702 GH_AW_VERSION: v0.71.1
703 GITHUB_API_URL: ${{ github.api_url }}
704 GITHUB_AW: true
705 GITHUB_COPILOT_INTEGRATION_ID: agentic-workflows
706 GITHUB_HEAD_REF: ${{ github.head_ref }}
707 GITHUB_MCP_SERVER_TOKEN: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}
708 GITHUB_REF_NAME: ${{ github.ref_name }}
709 GITHUB_SERVER_URL: ${{ github.server_url }}
710 GITHUB_STEP_SUMMARY: /tmp/gh-aw/agent-step-summary.md
711 GITHUB_WORKSPACE: ${{ github.workspace }}
712 GIT_AUTHOR_EMAIL: github-actions[bot]@users.noreply.github.com
713 GIT_AUTHOR_NAME: github-actions[bot]
714 GIT_COMMITTER_EMAIL: github-actions[bot]@users.noreply.github.com
715 GIT_COMMITTER_NAME: github-actions[bot]
716 XDG_CONFIG_HOME: /home/runner
717 - name: Detect Copilot errors
718 id: detect-copilot-errors
719 if: always()
720 continue-on-error: true
721 run: node "${RUNNER_TEMP}/gh-aw/actions/detect_copilot_errors.cjs"
722 - name: Configure Git credentials
723 env:
724 REPO_NAME: ${{ github.repository }}
725 SERVER_URL: ${{ github.server_url }}
726 GITHUB_TOKEN: ${{ github.token }}
727 run: |
728 git config --global user.email "github-actions[bot]@users.noreply.github.com"
729 git config --global user.name "github-actions[bot]"
730 git config --global am.keepcr true
731 # Re-authenticate git with GitHub token
732 SERVER_URL_STRIPPED="${SERVER_URL#https://}"
733 git remote set-url origin "https://x-access-token:${GITHUB_TOKEN}@${SERVER_URL_STRIPPED}/${REPO_NAME}.git"
734 echo "Git configured with standard GitHub Actions identity"
735 - name: Copy Copilot session state files to logs
736 if: always()
737 continue-on-error: true
738 run: bash "${RUNNER_TEMP}/gh-aw/actions/copy_copilot_session_state.sh"
739 - name: Stop MCP Gateway
740 if: always()
741 continue-on-error: true
742 env:
743 MCP_GATEWAY_PORT: ${{ steps.start-mcp-gateway.outputs.gateway-port }}
744 MCP_GATEWAY_API_KEY: ${{ steps.start-mcp-gateway.outputs.gateway-api-key }}
745 GATEWAY_PID: ${{ steps.start-mcp-gateway.outputs.gateway-pid }}
746 run: |
747 bash "${RUNNER_TEMP}/gh-aw/actions/stop_mcp_gateway.sh" "$GATEWAY_PID"
748 - name: Redact secrets in logs
749 if: always()
750 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
751 with:
752 script: |
753 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
754 setupGlobals(core, github, context, exec, io, getOctokit);
755 const { main } = require('${{ runner.temp }}/gh-aw/actions/redact_secrets.cjs');
756 await main();
757 env:
758 GH_AW_SECRET_NAMES: 'COPILOT_GITHUB_TOKEN,GH_AW_GITHUB_MCP_SERVER_TOKEN,GH_AW_GITHUB_TOKEN,GITHUB_TOKEN'
759 SECRET_COPILOT_GITHUB_TOKEN: ${{ secrets.COPILOT_GITHUB_TOKEN }}
760 SECRET_GH_AW_GITHUB_MCP_SERVER_TOKEN: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN }}
761 SECRET_GH_AW_GITHUB_TOKEN: ${{ secrets.GH_AW_GITHUB_TOKEN }}
762 SECRET_GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
763 - name: Append agent step summary
764 if: always()
765 run: bash "${RUNNER_TEMP}/gh-aw/actions/append_agent_step_summary.sh"
766 - name: Copy Safe Outputs
767 if: always()
768 env:
769 GH_AW_SAFE_OUTPUTS: ${{ steps.set-runtime-paths.outputs.GH_AW_SAFE_OUTPUTS }}
770 run: |
771 mkdir -p /tmp/gh-aw
772 cp "$GH_AW_SAFE_OUTPUTS" /tmp/gh-aw/safeoutputs.jsonl 2>/dev/null || true
773 - name: Ingest agent output
774 id: collect_output
775 if: always()
776 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
777 env:
778 GH_AW_SAFE_OUTPUTS: ${{ steps.set-runtime-paths.outputs.GH_AW_SAFE_OUTPUTS }}
779 GH_AW_ALLOWED_DOMAINS: "api.business.githubcopilot.com,api.enterprise.githubcopilot.com,api.github.com,api.githubcopilot.com,api.individual.githubcopilot.com,api.snapcraft.io,archive.ubuntu.com,azure.archive.ubuntu.com,crl.geotrust.com,crl.globalsign.com,crl.identrust.com,crl.sectigo.com,crl.thawte.com,crl.usertrust.com,crl.verisign.com,crl3.digicert.com,crl4.digicert.com,crls.ssl.com,github.com,host.docker.internal,json-schema.org,json.schemastore.org,keyserver.ubuntu.com,ocsp.digicert.com,ocsp.geotrust.com,ocsp.globalsign.com,ocsp.identrust.com,ocsp.sectigo.com,ocsp.ssl.com,ocsp.thawte.com,ocsp.usertrust.com,ocsp.verisign.com,packagecloud.io,packages.cloud.google.com,packages.microsoft.com,ppa.launchpad.net,raw.githubusercontent.com,registry.npmjs.org,s.symcb.com,s.symcd.com,security.ubuntu.com,telemetry.enterprise.githubcopilot.com,ts-crl.ws.symantec.com,ts-ocsp.ws.symantec.com,www.googleapis.com"
780 GITHUB_SERVER_URL: ${{ github.server_url }}
781 GITHUB_API_URL: ${{ github.api_url }}
782 with:
783 script: |
784 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
785 setupGlobals(core, github, context, exec, io, getOctokit);
786 const { main } = require('${{ runner.temp }}/gh-aw/actions/collect_ndjson_output.cjs');
787 await main();
788 - name: Parse agent logs for step summary
789 if: always()
790 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
791 env:
792 GH_AW_AGENT_OUTPUT: /tmp/gh-aw/sandbox/agent/logs/
793 with:
794 script: |
795 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
796 setupGlobals(core, github, context, exec, io, getOctokit);
797 const { main } = require('${{ runner.temp }}/gh-aw/actions/parse_copilot_log.cjs');
798 await main();
799 - name: Parse MCP Gateway logs for step summary
800 if: always()
801 id: parse-mcp-gateway
802 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
803 with:
804 script: |
805 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
806 setupGlobals(core, github, context, exec, io, getOctokit);
807 const { main } = require('${{ runner.temp }}/gh-aw/actions/parse_mcp_gateway_log.cjs');
808 await main();
809 - name: Print firewall logs
810 if: always()
811 continue-on-error: true
812 env:
813 AWF_LOGS_DIR: /tmp/gh-aw/sandbox/firewall/logs
814 run: |
815 # Fix permissions on firewall logs/audit dirs so they can be uploaded as artifacts
816 # AWF runs with sudo, creating files owned by root
817 sudo chmod -R a+r /tmp/gh-aw/sandbox/firewall 2>/dev/null || true
818 # Only run awf logs summary if awf command exists (it may not be installed if workflow failed before install step)
819 if command -v awf &> /dev/null; then
820 awf logs summary | tee -a "$GITHUB_STEP_SUMMARY"
821 else
822 echo 'AWF binary not installed, skipping firewall log summary'
823 fi
824 - name: Parse token usage for step summary
825 if: always()
826 continue-on-error: true
827 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
828 with:
829 script: |
830 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
831 setupGlobals(core, github, context, exec, io, getOctokit);
832 const { main } = require('${{ runner.temp }}/gh-aw/actions/parse_token_usage.cjs');
833 await main();
834 - name: Write agent output placeholder if missing
835 if: always()
836 run: |
837 if [ ! -f /tmp/gh-aw/agent_output.json ]; then
838 echo '{"items":[]}' > /tmp/gh-aw/agent_output.json
839 fi
840 - name: Upload agent artifacts
841 if: always()
842 continue-on-error: true
843 uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
844 with:
845 name: agent
846 path: |
847 /tmp/gh-aw/aw-prompts/prompt.txt
848 /tmp/gh-aw/sandbox/agent/logs/
849 /tmp/gh-aw/redacted-urls.log
850 /tmp/gh-aw/mcp-logs/
851 /tmp/gh-aw/agent_usage.json
852 /tmp/gh-aw/agent-stdio.log
853 /tmp/gh-aw/agent/
854 /tmp/gh-aw/github_rate_limits.jsonl
855 /tmp/gh-aw/safeoutputs.jsonl
856 /tmp/gh-aw/agent_output.json
857 /tmp/gh-aw/aw-*.patch
858 /tmp/gh-aw/aw-*.bundle
859 /tmp/gh-aw/sandbox/firewall/logs/
860 /tmp/gh-aw/sandbox/firewall/audit/
861 if-no-files-found: ignore
862
863 conclusion:
864 needs:
865 - activation
866 - agent
867 - detection
868 - safe_outputs
869 if: >
870 always() && (needs.agent.result != 'skipped' || needs.activation.outputs.lockdown_check_failed == 'true' ||
871 needs.activation.outputs.stale_lock_file_failed == 'true')
872 runs-on: ubuntu-slim
873 permissions:
874 contents: read
875 issues: write
876 concurrency:
877 group: "gh-aw-conclusion-bump-tcgc-csharp"
878 cancel-in-progress: false
879 outputs:
880 incomplete_count: ${{ steps.report_incomplete.outputs.incomplete_count }}
881 noop_message: ${{ steps.noop.outputs.noop_message }}
882 tools_reported: ${{ steps.missing_tool.outputs.tools_reported }}
883 total_count: ${{ steps.missing_tool.outputs.total_count }}
884 steps:
885 - name: Setup Scripts
886 id: setup
887 uses: github/gh-aw-actions/setup@239aec45b78c8799417efdd5bc6d8cc036629ec1 # v0.71.1
888 with:
889 destination: ${{ runner.temp }}/gh-aw/actions
890 job-name: ${{ github.job }}
891 trace-id: ${{ needs.activation.outputs.setup-trace-id }}
892 - name: Download agent output artifact
893 id: download-agent-output
894 continue-on-error: true
895 uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
896 with:
897 name: agent
898 path: /tmp/gh-aw/
899 - name: Setup agent output environment variable
900 id: setup-agent-output-env
901 if: steps.download-agent-output.outcome == 'success'
902 run: |
903 mkdir -p /tmp/gh-aw/
904 find "/tmp/gh-aw/" -type f -print
905 echo "GH_AW_AGENT_OUTPUT=/tmp/gh-aw/agent_output.json" >> "$GITHUB_OUTPUT"
906 - name: Process no-op messages
907 id: noop
908 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
909 env:
910 GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }}
911 GH_AW_NOOP_MAX: "1"
912 GH_AW_WORKFLOW_NAME: "Agentic TCGC Bump for http-client-csharp"
913 GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
914 GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }}
915 GH_AW_NOOP_REPORT_AS_ISSUE: "false"
916 with:
917 github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}
918 script: |
919 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
920 setupGlobals(core, github, context, exec, io, getOctokit);
921 const { main } = require('${{ runner.temp }}/gh-aw/actions/handle_noop_message.cjs');
922 await main();
923 - name: Log detection run
924 id: detection_runs
925 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
926 env:
927 GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }}
928 GH_AW_WORKFLOW_NAME: "Agentic TCGC Bump for http-client-csharp"
929 GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
930 GH_AW_DETECTION_CONCLUSION: ${{ needs.detection.outputs.detection_conclusion }}
931 GH_AW_DETECTION_REASON: ${{ needs.detection.outputs.detection_reason }}
932 with:
933 github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}
934 script: |
935 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
936 setupGlobals(core, github, context, exec, io, getOctokit);
937 const { main } = require('${{ runner.temp }}/gh-aw/actions/handle_detection_runs.cjs');
938 await main();
939 - name: Record missing tool
940 id: missing_tool
941 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
942 env:
943 GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }}
944 GH_AW_MISSING_TOOL_CREATE_ISSUE: "true"
945 GH_AW_WORKFLOW_NAME: "Agentic TCGC Bump for http-client-csharp"
946 with:
947 github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}
948 script: |
949 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
950 setupGlobals(core, github, context, exec, io, getOctokit);
951 const { main } = require('${{ runner.temp }}/gh-aw/actions/missing_tool.cjs');
952 await main();
953 - name: Record incomplete
954 id: report_incomplete
955 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
956 env:
957 GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }}
958 GH_AW_REPORT_INCOMPLETE_CREATE_ISSUE: "true"
959 GH_AW_WORKFLOW_NAME: "Agentic TCGC Bump for http-client-csharp"
960 with:
961 github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}
962 script: |
963 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
964 setupGlobals(core, github, context, exec, io, getOctokit);
965 const { main } = require('${{ runner.temp }}/gh-aw/actions/report_incomplete_handler.cjs');
966 await main();
967 - name: Handle agent failure
968 id: handle_agent_failure
969 if: always()
970 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
971 env:
972 GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }}
973 GH_AW_WORKFLOW_NAME: "Agentic TCGC Bump for http-client-csharp"
974 GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
975 GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }}
976 GH_AW_WORKFLOW_ID: "bump-tcgc-csharp"
977 GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURS: "168"
978 GH_AW_ENGINE_ID: "copilot"
979 GH_AW_SECRET_VERIFICATION_RESULT: ${{ needs.activation.outputs.secret_verification_result }}
980 GH_AW_CHECKOUT_PR_SUCCESS: ${{ needs.agent.outputs.checkout_pr_success }}
981 GH_AW_INFERENCE_ACCESS_ERROR: ${{ needs.agent.outputs.inference_access_error }}
982 GH_AW_MCP_POLICY_ERROR: ${{ needs.agent.outputs.mcp_policy_error }}
983 GH_AW_AGENTIC_ENGINE_TIMEOUT: ${{ needs.agent.outputs.agentic_engine_timeout }}
984 GH_AW_MODEL_NOT_SUPPORTED_ERROR: ${{ needs.agent.outputs.model_not_supported_error }}
985 GH_AW_ASSIGNMENT_ERRORS: ${{ needs.safe_outputs.outputs.assign_to_agent_assignment_errors }}
986 GH_AW_ASSIGNMENT_ERROR_COUNT: ${{ needs.safe_outputs.outputs.assign_to_agent_assignment_error_count }}
987 GH_AW_ASSIGN_COPILOT_FAILURE_COUNT: ${{ needs.safe_outputs.outputs.assign_copilot_failure_count }}
988 GH_AW_ASSIGN_COPILOT_ERRORS: ${{ needs.safe_outputs.outputs.assign_copilot_errors }}
989 GH_AW_LOCKDOWN_CHECK_FAILED: ${{ needs.activation.outputs.lockdown_check_failed }}
990 GH_AW_STALE_LOCK_FILE_FAILED: ${{ needs.activation.outputs.stale_lock_file_failed }}
991 GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"\\u003e Generated by [{workflow_name}]({run_url})\",\"footerInstall\":\"\\u003c!-- --\\u003e\"}"
992 GH_AW_GROUP_REPORTS: "false"
993 GH_AW_FAILURE_REPORT_AS_ISSUE: "true"
994 GH_AW_TIMEOUT_MINUTES: "15"
995 with:
996 github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}
997 script: |
998 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
999 setupGlobals(core, github, context, exec, io, getOctokit);
1000 const { main } = require('${{ runner.temp }}/gh-aw/actions/handle_agent_failure.cjs');
1001 await main();
1002
1003 detection:
1004 needs:
1005 - activation
1006 - agent
1007 if: >
1008 always() && needs.agent.result != 'skipped' && (needs.agent.outputs.output_types != '' || needs.agent.outputs.has_patch == 'true')
1009 runs-on: ubuntu-latest
1010 permissions:
1011 contents: read
1012 outputs:
1013 detection_conclusion: ${{ steps.detection_conclusion.outputs.conclusion }}
1014 detection_reason: ${{ steps.detection_conclusion.outputs.reason }}
1015 detection_success: ${{ steps.detection_conclusion.outputs.success }}
1016 steps:
1017 - name: Setup Scripts
1018 id: setup
1019 uses: github/gh-aw-actions/setup@239aec45b78c8799417efdd5bc6d8cc036629ec1 # v0.71.1
1020 with:
1021 destination: ${{ runner.temp }}/gh-aw/actions
1022 job-name: ${{ github.job }}
1023 trace-id: ${{ needs.activation.outputs.setup-trace-id }}
1024 - name: Download agent output artifact
1025 id: download-agent-output
1026 continue-on-error: true
1027 uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
1028 with:
1029 name: agent
1030 path: /tmp/gh-aw/
1031 - name: Setup agent output environment variable
1032 id: setup-agent-output-env
1033 if: steps.download-agent-output.outcome == 'success'
1034 run: |
1035 mkdir -p /tmp/gh-aw/
1036 find "/tmp/gh-aw/" -type f -print
1037 echo "GH_AW_AGENT_OUTPUT=/tmp/gh-aw/agent_output.json" >> "$GITHUB_OUTPUT"
1038 - name: Checkout repository for patch context
1039 if: needs.agent.outputs.has_patch == 'true'
1040 uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
1041 with:
1042 persist-credentials: false
1043 # --- Threat Detection ---
1044 - name: Clean stale firewall files from agent artifact
1045 run: |
1046 rm -rf /tmp/gh-aw/sandbox/firewall/logs
1047 rm -rf /tmp/gh-aw/sandbox/firewall/audit
1048 - name: Download container images
1049 run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.25.28@sha256:a8834e285807654bf680154faa710d43fe4365a0868142f5c20e48c85e137a7a ghcr.io/github/gh-aw-firewall/api-proxy:0.25.28@sha256:93290f2393752252911bd7c39a047f776c0b53063575e7bde4e304962a9a61cb ghcr.io/github/gh-aw-firewall/squid:0.25.28@sha256:844c18280f82cd1b06345eb2f4e91966b34185bfc51c9f237c3e022e848fb474
1050 - name: Check if detection needed
1051 id: detection_guard
1052 if: always()
1053 env:
1054 OUTPUT_TYPES: ${{ needs.agent.outputs.output_types }}
1055 HAS_PATCH: ${{ needs.agent.outputs.has_patch }}
1056 run: |
1057 if [[ -n "$OUTPUT_TYPES" || "$HAS_PATCH" == "true" ]]; then
1058 echo "run_detection=true" >> "$GITHUB_OUTPUT"
1059 echo "Detection will run: output_types=$OUTPUT_TYPES, has_patch=$HAS_PATCH"
1060 else
1061 echo "run_detection=false" >> "$GITHUB_OUTPUT"
1062 echo "Detection skipped: no agent outputs or patches to analyze"
1063 fi
1064 - name: Clear MCP configuration for detection
1065 if: always() && steps.detection_guard.outputs.run_detection == 'true'
1066 run: |
1067 rm -f "${RUNNER_TEMP}/gh-aw/mcp-config/mcp-servers.json"
1068 rm -f /home/runner/.copilot/mcp-config.json
1069 rm -f "$GITHUB_WORKSPACE/.gemini/settings.json"
1070 - name: Prepare threat detection files
1071 if: always() && steps.detection_guard.outputs.run_detection == 'true'
1072 run: |
1073 mkdir -p /tmp/gh-aw/threat-detection/aw-prompts
1074 cp /tmp/gh-aw/aw-prompts/prompt.txt /tmp/gh-aw/threat-detection/aw-prompts/prompt.txt 2>/dev/null || true
1075 cp /tmp/gh-aw/agent_output.json /tmp/gh-aw/threat-detection/agent_output.json 2>/dev/null || true
1076 for f in /tmp/gh-aw/aw-*.patch; do
1077 [ -f "$f" ] && cp "$f" /tmp/gh-aw/threat-detection/ 2>/dev/null || true
1078 done
1079 for f in /tmp/gh-aw/aw-*.bundle; do
1080 [ -f "$f" ] && cp "$f" /tmp/gh-aw/threat-detection/ 2>/dev/null || true
1081 done
1082 echo "Prepared threat detection files:"
1083 ls -la /tmp/gh-aw/threat-detection/ 2>/dev/null || true
1084 - name: Setup threat detection
1085 if: always() && steps.detection_guard.outputs.run_detection == 'true'
1086 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
1087 env:
1088 WORKFLOW_NAME: "Agentic TCGC Bump for http-client-csharp"
1089 WORKFLOW_DESCRIPTION: "Daily TCGC version watcher for the http-client-csharp emitter. Checks the npm\nregistry for new non-dev releases of @azure-tools/typespec-client-generator-core\nand, when a newer stable version is available and no equivalent issue already\nexists, files a tracking issue assigned to GitHub Copilot to perform the upgrade."
1090 HAS_PATCH: ${{ needs.agent.outputs.has_patch }}
1091 with:
1092 script: |
1093 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
1094 setupGlobals(core, github, context, exec, io, getOctokit);
1095 const { main } = require('${{ runner.temp }}/gh-aw/actions/setup_threat_detection.cjs');
1096 await main();
1097 - name: Ensure threat-detection directory and log
1098 if: always() && steps.detection_guard.outputs.run_detection == 'true'
1099 run: |
1100 mkdir -p /tmp/gh-aw/threat-detection
1101 touch /tmp/gh-aw/threat-detection/detection.log
1102 - name: Setup Node.js
1103 uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
1104 with:
1105 node-version: '24'
1106 package-manager-cache: false
1107 - name: Install GitHub Copilot CLI
1108 run: bash "${RUNNER_TEMP}/gh-aw/actions/install_copilot_cli.sh" 1.0.35
1109 env:
1110 GH_HOST: github.com
1111 - name: Install AWF binary
1112 run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.25.28
1113 - name: Execute GitHub Copilot CLI
1114 if: always() && steps.detection_guard.outputs.run_detection == 'true'
1115 id: detection_agentic_execution
1116 # Copilot CLI tool arguments (sorted):
1117 timeout-minutes: 20
1118 run: |
1119 set -o pipefail
1120 touch /tmp/gh-aw/agent-step-summary.md
1121 GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true)
1122 export GH_AW_NODE_BIN
1123 (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log)
1124 # shellcheck disable=SC1003
1125 sudo -E awf --container-workdir "${GITHUB_WORKSPACE}" --mount "${RUNNER_TEMP}/gh-aw:${RUNNER_TEMP}/gh-aw:ro" --mount "${RUNNER_TEMP}/gh-aw:/host${RUNNER_TEMP}/gh-aw:ro" --env-all --exclude-env COPILOT_GITHUB_TOKEN --allow-domains api.business.githubcopilot.com,api.enterprise.githubcopilot.com,api.github.com,api.githubcopilot.com,api.individual.githubcopilot.com,github.com,host.docker.internal,telemetry.enterprise.githubcopilot.com --log-level info --proxy-logs-dir /tmp/gh-aw/sandbox/firewall/logs --audit-dir /tmp/gh-aw/sandbox/firewall/audit --enable-host-access --allow-host-ports 80,443,8080 --image-tag 0.25.28,squid=sha256:844c18280f82cd1b06345eb2f4e91966b34185bfc51c9f237c3e022e848fb474,agent=sha256:a8834e285807654bf680154faa710d43fe4365a0868142f5c20e48c85e137a7a,api-proxy=sha256:93290f2393752252911bd7c39a047f776c0b53063575e7bde4e304962a9a61cb,cli-proxy=sha256:fdf310e4678ce58d248c466b89399e9680a3003038fd19322c388559016aaac7 --skip-pull --enable-api-proxy \
1126 -- /bin/bash -c 'GH_AW_NODE_EXEC="${GH_AW_NODE_BIN:-}"; if [ -z "$GH_AW_NODE_EXEC" ] || [ ! -x "$GH_AW_NODE_EXEC" ]; then GH_AW_NODE_EXEC="$(command -v node 2>/dev/null || echo node)"; fi; "$GH_AW_NODE_EXEC" ${RUNNER_TEMP}/gh-aw/actions/copilot_driver.cjs /usr/local/bin/copilot --add-dir /tmp/gh-aw/ --log-level all --log-dir /tmp/gh-aw/sandbox/agent/logs/ --disable-builtin-mcps --no-ask-user --allow-all-tools --add-dir "${GITHUB_WORKSPACE}" --prompt-file /tmp/gh-aw/aw-prompts/prompt.txt' 2>&1 | tee -a /tmp/gh-aw/threat-detection/detection.log
1127 env:
1128 COPILOT_AGENT_RUNNER_TYPE: STANDALONE
1129 COPILOT_API_KEY: dummy-byok-key-for-offline-mode
1130 COPILOT_GITHUB_TOKEN: ${{ secrets.COPILOT_GITHUB_TOKEN }}
1131 COPILOT_MODEL: ${{ vars.GH_AW_MODEL_DETECTION_COPILOT || 'claude-sonnet-4.6' }}
1132 GH_AW_PHASE: detection
1133 GH_AW_PROMPT: /tmp/gh-aw/aw-prompts/prompt.txt
1134 GH_AW_VERSION: v0.71.1
1135 GITHUB_API_URL: ${{ github.api_url }}
1136 GITHUB_AW: true
1137 GITHUB_COPILOT_INTEGRATION_ID: agentic-workflows
1138 GITHUB_HEAD_REF: ${{ github.head_ref }}
1139 GITHUB_REF_NAME: ${{ github.ref_name }}
1140 GITHUB_SERVER_URL: ${{ github.server_url }}
1141 GITHUB_STEP_SUMMARY: /tmp/gh-aw/agent-step-summary.md
1142 GITHUB_WORKSPACE: ${{ github.workspace }}
1143 GIT_AUTHOR_EMAIL: github-actions[bot]@users.noreply.github.com
1144 GIT_AUTHOR_NAME: github-actions[bot]
1145 GIT_COMMITTER_EMAIL: github-actions[bot]@users.noreply.github.com
1146 GIT_COMMITTER_NAME: github-actions[bot]
1147 XDG_CONFIG_HOME: /home/runner
1148 - name: Upload threat detection log
1149 if: always() && steps.detection_guard.outputs.run_detection == 'true'
1150 uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
1151 with:
1152 name: detection
1153 path: /tmp/gh-aw/threat-detection/detection.log
1154 if-no-files-found: ignore
1155 - name: Parse and conclude threat detection
1156 id: detection_conclusion
1157 if: always()
1158 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
1159 env:
1160 RUN_DETECTION: ${{ steps.detection_guard.outputs.run_detection }}
1161 GH_AW_DETECTION_CONTINUE_ON_ERROR: "true"
1162 with:
1163 script: |
1164 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
1165 setupGlobals(core, github, context, exec, io, getOctokit);
1166 const { main } = require('${{ runner.temp }}/gh-aw/actions/parse_threat_detection_results.cjs');
1167 await main();
1168
1169 safe_outputs:
1170 needs:
1171 - activation
1172 - agent
1173 - detection
1174 if: (!cancelled()) && needs.agent.result != 'skipped' && needs.detection.result == 'success'
1175 runs-on: ubuntu-slim
1176 permissions:
1177 contents: read
1178 issues: write
1179 timeout-minutes: 15
1180 env:
1181 GH_AW_CALLER_WORKFLOW_ID: "${{ github.repository }}/bump-tcgc-csharp"
1182 GH_AW_DETECTION_CONCLUSION: ${{ needs.detection.outputs.detection_conclusion }}
1183 GH_AW_DETECTION_REASON: ${{ needs.detection.outputs.detection_reason }}
1184 GH_AW_EFFECTIVE_TOKENS: ${{ needs.agent.outputs.effective_tokens }}
1185 GH_AW_ENGINE_ID: "copilot"
1186 GH_AW_ENGINE_MODEL: ${{ needs.agent.outputs.model }}
1187 GH_AW_ENGINE_VERSION: "1.0.35"
1188 GH_AW_SAFE_OUTPUT_MESSAGES: "{\"footer\":\"\\u003e Generated by [{workflow_name}]({run_url})\",\"footerInstall\":\"\\u003c!-- --\\u003e\"}"
1189 GH_AW_WORKFLOW_ID: "bump-tcgc-csharp"
1190 GH_AW_WORKFLOW_NAME: "Agentic TCGC Bump for http-client-csharp"
1191 outputs:
1192 assign_copilot_errors: ${{ steps.assign_copilot_to_created_issues.outputs.assign_copilot_errors }}
1193 assign_copilot_failure_count: ${{ steps.assign_copilot_to_created_issues.outputs.assign_copilot_failure_count }}
1194 assign_to_agent_assigned: ${{ steps.process_safe_outputs.outputs.assign_to_agent_assigned }}
1195 assign_to_agent_assignment_error_count: ${{ steps.process_safe_outputs.outputs.assign_to_agent_assignment_error_count }}
1196 assign_to_agent_assignment_errors: ${{ steps.process_safe_outputs.outputs.assign_to_agent_assignment_errors }}
1197 code_push_failure_count: ${{ steps.process_safe_outputs.outputs.code_push_failure_count }}
1198 code_push_failure_errors: ${{ steps.process_safe_outputs.outputs.code_push_failure_errors }}
1199 create_discussion_error_count: ${{ steps.process_safe_outputs.outputs.create_discussion_error_count }}
1200 create_discussion_errors: ${{ steps.process_safe_outputs.outputs.create_discussion_errors }}
1201 created_issue_number: ${{ steps.process_safe_outputs.outputs.created_issue_number }}
1202 created_issue_url: ${{ steps.process_safe_outputs.outputs.created_issue_url }}
1203 process_safe_outputs_processed_count: ${{ steps.process_safe_outputs.outputs.processed_count }}
1204 process_safe_outputs_temporary_id_map: ${{ steps.process_safe_outputs.outputs.temporary_id_map }}
1205 steps:
1206 - name: Setup Scripts
1207 id: setup
1208 uses: github/gh-aw-actions/setup@239aec45b78c8799417efdd5bc6d8cc036629ec1 # v0.71.1
1209 with:
1210 destination: ${{ runner.temp }}/gh-aw/actions
1211 job-name: ${{ github.job }}
1212 trace-id: ${{ needs.activation.outputs.setup-trace-id }}
1213 - name: Download agent output artifact
1214 id: download-agent-output
1215 continue-on-error: true
1216 uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
1217 with:
1218 name: agent
1219 path: /tmp/gh-aw/
1220 - name: Setup agent output environment variable
1221 id: setup-agent-output-env
1222 if: steps.download-agent-output.outcome == 'success'
1223 run: |
1224 mkdir -p /tmp/gh-aw/
1225 find "/tmp/gh-aw/" -type f -print
1226 echo "GH_AW_AGENT_OUTPUT=/tmp/gh-aw/agent_output.json" >> "$GITHUB_OUTPUT"
1227 - name: Configure GH_HOST for enterprise compatibility
1228 id: ghes-host-config
1229 shell: bash
1230 run: |
1231 # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct
1232 # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op.
1233 GH_HOST="${GITHUB_SERVER_URL#https://}"
1234 GH_HOST="${GH_HOST#http://}"
1235 echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV"
1236 - name: Process Safe Outputs
1237 id: process_safe_outputs
1238 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
1239 env:
1240 GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }}
1241 GH_AW_ALLOWED_DOMAINS: "api.business.githubcopilot.com,api.enterprise.githubcopilot.com,api.github.com,api.githubcopilot.com,api.individual.githubcopilot.com,api.snapcraft.io,archive.ubuntu.com,azure.archive.ubuntu.com,crl.geotrust.com,crl.globalsign.com,crl.identrust.com,crl.sectigo.com,crl.thawte.com,crl.usertrust.com,crl.verisign.com,crl3.digicert.com,crl4.digicert.com,crls.ssl.com,github.com,host.docker.internal,json-schema.org,json.schemastore.org,keyserver.ubuntu.com,ocsp.digicert.com,ocsp.geotrust.com,ocsp.globalsign.com,ocsp.identrust.com,ocsp.sectigo.com,ocsp.ssl.com,ocsp.thawte.com,ocsp.usertrust.com,ocsp.verisign.com,packagecloud.io,packages.cloud.google.com,packages.microsoft.com,ppa.launchpad.net,raw.githubusercontent.com,registry.npmjs.org,s.symcb.com,s.symcd.com,security.ubuntu.com,telemetry.enterprise.githubcopilot.com,ts-crl.ws.symantec.com,ts-ocsp.ws.symantec.com,www.googleapis.com"
1242 GITHUB_SERVER_URL: ${{ github.server_url }}
1243 GITHUB_API_URL: ${{ github.api_url }}
1244 GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"assign_to_agent\":{\"max\":1,\"model\":\"claude-opus-4.6\",\"name\":\"copilot\"},\"create_issue\":{\"assignees\":[\"copilot\"],\"labels\":[\"emitter:client:csharp\"],\"max\":1,\"title_prefix\":\"Bump TCGC to \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":1,\"report-as-issue\":\"false\"},\"report_incomplete\":{}}"
1245 GH_AW_ASSIGN_COPILOT: "true"
1246 GH_AW_ASSIGN_TO_AGENT_TOKEN: ${{ secrets.GH_AW_AGENT_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}
1247 with:
1248 github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}
1249 script: |
1250 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
1251 setupGlobals(core, github, context, exec, io, getOctokit);
1252 const { main } = require('${{ runner.temp }}/gh-aw/actions/safe_output_handler_manager.cjs');
1253 await main();
1254 - name: Assign Copilot to created issues
1255 id: assign_copilot_to_created_issues
1256 if: steps.process_safe_outputs.outputs.issues_to_assign_copilot != ''
1257 continue-on-error: true
1258 uses: actions/github-script@373c709c69115d41ff229c7e5df9f8788daa9553 # v9
1259 env:
1260 GH_AW_ISSUES_TO_ASSIGN_COPILOT: ${{ steps.process_safe_outputs.outputs.issues_to_assign_copilot }}
1261 with:
1262 github-token: ${{ secrets.GH_AW_AGENT_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}
1263 script: |
1264 const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs');
1265 setupGlobals(core, github, context, exec, io, getOctokit);
1266 const { main } = require('${{ runner.temp }}/gh-aw/actions/assign_copilot_to_created_issues.cjs');
1267 await main();
1268 - name: Upload Safe Outputs Items
1269 if: always()
1270 uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
1271 with:
1272 name: safe-outputs-items
1273 path: |
1274 /tmp/gh-aw/safe-output-items.jsonl
1275 /tmp/gh-aw/temporary-id-map.json
1276 if-no-files-found: ignore
1277
1278