diff --git a/.github/workflows/aw-actions-update.lock.yml b/.github/workflows/aw-actions-update.lock.yml index 14d382f59335..13bc20767b49 100644 --- a/.github/workflows/aw-actions-update.lock.yml +++ b/.github/workflows/aw-actions-update.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"9ff22fe7fef57bf9aca4f49d1eea0bc5fd03603d45c2a78839bfb528f490e78e","body_hash":"9340659e4630e685c3141a7f94e1b526e78bf14ef72d001b81122eeca3fffc10","compiler_version":"v0.80.9","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.63"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"7f07eba73059bd134ac83e06f7f0c0a37ddaa4e119a9407c2658f151fffc009c","body_hash":"bb2bfc0e6a2ebfc33e425bfea01f1068871e82428ceced732e52443c07cabd82","compiler_version":"v0.80.9","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.63"}} # gh-aw-manifest: {"version":1,"secrets":["COPILOT_PAT_0","COPILOT_PAT_1","COPILOT_PAT_2","COPILOT_PAT_3","COPILOT_PAT_4","COPILOT_PAT_5","COPILOT_PAT_6","COPILOT_PAT_7","COPILOT_PAT_8","COPILOT_PAT_9","GH_AW_CI_TRIGGER_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"27d5ce7f107fe9357f9df03efb73ab90386fccae","version":"v5.0.5"},{"repo":"actions/cache/save","sha":"27d5ce7f107fe9357f9df03efb73ab90386fccae","version":"v5.0.5"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/checkout","sha":"de0fac2e4500dabe0009e67214ff5f5447ce83dd","version":"v6.0.2"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"8c7d04ebf1ece56cd381446125da3e0f6896294a","version":"v0.80.9"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.7","digest":"sha256:aae231e4635c8999d039c132f1602d3df850fe9b84a00aa2b5ac981179b5661c","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.7@sha256:aae231e4635c8999d039c132f1602d3df850fe9b84a00aa2b5ac981179b5661c"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.7","digest":"sha256:009caf2e3d88fa77b64e9a03a95a228fc58db0f1701c6d324b29ba5a3c7c79b6","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.7@sha256:009caf2e3d88fa77b64e9a03a95a228fc58db0f1701c6d324b29ba5a3c7c79b6"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.7","digest":"sha256:deb1d4e19de62d51cee0508057a596a19315c3423ada4d675cad136dc8037c96","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.7@sha256:deb1d4e19de62d51cee0508057a596a19315c3423ada4d675cad136dc8037c96"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.27","digest":"sha256:fe984bddde4ec05d756d9043edb0a32912e6b7b72f6a121b1082f29221421cc7","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.27@sha256:fe984bddde4ec05d756d9043edb0a32912e6b7b72f6a121b1082f29221421cc7"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.4.0","digest":"sha256:2afb26356481d1a350e14544a6e160f7f7ec1561a1ea309b823665abf0309036","pinned_image":"ghcr.io/github/github-mcp-server:v1.4.0@sha256:2afb26356481d1a350e14544a6e160f7f7ec1561a1ea309b823665abf0309036"}]} # This file was automatically generated by gh-aw (v0.80.9). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # @@ -908,6 +908,7 @@ jobs: GH_AW_SAFE_OUTPUTS: ${{ steps.set-runtime-paths.outputs.GH_AW_SAFE_OUTPUTS }} GH_AW_TIMEOUT_MINUTES: 15 GH_AW_VERSION: v0.80.9 + GH_TOKEN: ${{ github.token }} GITHUB_API_URL: ${{ github.api_url }} GITHUB_AW: true GITHUB_COPILOT_INTEGRATION_ID: agentic-workflows @@ -1528,6 +1529,7 @@ jobs: GH_AW_PROMPT: /tmp/gh-aw/aw-prompts/prompt.txt GH_AW_TIMEOUT_MINUTES: 20 GH_AW_VERSION: v0.80.9 + GH_TOKEN: ${{ github.token }} GITHUB_API_URL: ${{ github.api_url }} GITHUB_AW: true GITHUB_COPILOT_INTEGRATION_ID: agentic-workflows diff --git a/.github/workflows/aw-actions-update.md b/.github/workflows/aw-actions-update.md index 75c6aeee3870..b6a5a9374384 100644 --- a/.github/workflows/aw-actions-update.md +++ b/.github/workflows/aw-actions-update.md @@ -52,6 +52,9 @@ tracker-id: aw-actions-update engine: id: copilot env: + # Authenticate the agent's `gh` CLI commands with this workflow's read-only + # GitHub Actions token, not the Copilot inference PAT. + GH_TOKEN: ${{ github.token }} COPILOT_GITHUB_TOKEN: | ${{ case( needs.pat_pool.outputs.pat_number == '0', secrets.COPILOT_PAT_0, @@ -129,19 +132,26 @@ so an unrelated user-opened PR with a colliding title cannot suppress the refres ## Step 1 — Ensure the gh-aw CLI is available at the pinned version The `gh aw` command comes from the `github/gh-aw` gh extension, which may not be preinstalled on -the runner. **Pin the install to `v0.80.9`** — the same `compiler_version` all committed -`.github/workflows/*.lock.yml` files were built with. `gh aw update` caps native action-pin -resolution at the CLI's own version, so a newer CLI would refresh `actions-lock.json` in a way -that no longer matches the v0.80.9-compiled locks (version skew). Bumping gh-aw is a deliberate, -coordinated change handled by the separate `aw-version-update` runbook — not something this -weekly pin-refresher should do implicitly. +the runner. Read this workflow's required version from the `compiler_version` metadata in its +committed lock file. `gh aw update` caps native action-pin resolution at the CLI's own version, so +a newer CLI would refresh `actions-lock.json` in a way that no longer matches the compiled lock +(version skew). Bumping gh-aw is a deliberate, coordinated change handled by the separate +`aw-version-update` runbook — not something this weekly pin-refresher should do implicitly. Remove any pre-installed copy, then install the pinned tag. **Fail closed** (log and exit without -creating a PR) if the pinned install does not succeed — never silently continue on a stale or -wrong-version CLI. +creating a PR) if the lock metadata is invalid or the pinned install does not succeed — never +silently continue on a stale or wrong-version CLI. The workflow sets `GH_TOKEN` from its +read-only GitHub Actions token so the GitHub CLI can remove a preinstalled extension and install +the lock-pinned release without using the Copilot inference PAT. ```bash -GH_AW_PINNED_VERSION="v0.80.9" # keep in sync with the committed *.lock.yml compiler_version +GH_AW_LOCK_FILE=".github/workflows/aw-actions-update.lock.yml" +GH_AW_PINNED_VERSION="$(sed -nE '1s/^# gh-aw-metadata: .*"compiler_version":"([^"]+)".*$/\1/p' "$GH_AW_LOCK_FILE")" +if ! printf '%s\n' "$GH_AW_PINNED_VERSION" | grep -Eq '^v[0-9]+\.[0-9]+\.[0-9]+$'; then + echo "Could not read a valid gh-aw compiler_version from $GH_AW_LOCK_FILE; not creating a PR." + exit 0 +fi + gh extension remove gh-aw 2>/dev/null || true if ! gh extension install github/gh-aw --pin "$GH_AW_PINNED_VERSION"; then echo "Failed to install gh-aw $GH_AW_PINNED_VERSION; not creating a PR."