Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .changeset/patch-bump-awf-v0-27-7.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

38 changes: 19 additions & 19 deletions .github/workflows/ab-testing-advisor.lock.yml

Large diffs are not rendered by default.

26 changes: 13 additions & 13 deletions .github/workflows/ace-editor.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/agent-performance-analyzer.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/agent-persona-explorer.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/agentic-token-audit.lock.yml

Large diffs are not rendered by default.

28 changes: 14 additions & 14 deletions .github/workflows/agentic-token-optimizer.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/agentic-token-trend-audit.lock.yml

Large diffs are not rendered by default.

28 changes: 14 additions & 14 deletions .github/workflows/ai-moderator.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/api-consumption-report.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/approach-validator.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/archie.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/architecture-guardian.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/artifacts-summary.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/audit-workflows.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/auto-triage-issues.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/avenger.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/aw-failure-investigator.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/blog-auditor.lock.yml

Large diffs are not rendered by default.

24 changes: 12 additions & 12 deletions .github/workflows/bot-detection.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/brave.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/breaking-change-checker.lock.yml

Large diffs are not rendered by default.

26 changes: 13 additions & 13 deletions .github/workflows/changeset.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/chaos-pr-bundle-fuzzer.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/ci-coach.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/ci-doctor.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/claude-code-user-docs-review.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/cli-consistency-checker.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/cli-version-checker.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/cloclo.lock.yml

Large diffs are not rendered by default.

40 changes: 20 additions & 20 deletions .github/workflows/code-scanning-fixer.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/code-simplifier.lock.yml

Large diffs are not rendered by default.

24 changes: 12 additions & 12 deletions .github/workflows/codex-github-remote-mcp-test.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/commit-changes-analyzer.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/constraint-solving-potd.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/contribution-check.lock.yml

Large diffs are not rendered by default.

40 changes: 20 additions & 20 deletions .github/workflows/copilot-agent-analysis.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/copilot-centralization-drilldown.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/copilot-centralization-optimizer.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/copilot-cli-deep-research.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/copilot-opt.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/copilot-pr-merged-report.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/copilot-pr-nlp-analysis.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/copilot-pr-prompt-analysis.lock.yml

Large diffs are not rendered by default.

40 changes: 20 additions & 20 deletions .github/workflows/copilot-session-insights.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/craft.lock.yml

Large diffs are not rendered by default.

40 changes: 20 additions & 20 deletions .github/workflows/daily-agent-of-the-day-blog-writer.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/daily-agentrx-trace-optimizer.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/daily-ambient-context-optimizer.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/daily-architecture-diagram.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/daily-assign-issue-to-user.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/daily-aw-cross-repo-compile-check.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/daily-awf-spec-compiler-surfacing.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/daily-byok-ollama-test.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-cache-strategy-analyzer.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-caveman-optimizer.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/daily-choice-test.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-cli-performance.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/daily-cli-tools-tester.lock.yml

Large diffs are not rendered by default.

42 changes: 21 additions & 21 deletions .github/workflows/daily-code-metrics.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-community-attribution.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-compiler-quality.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/daily-compiler-threat-spec-optimizer.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/daily-credit-limit-test.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-doc-healer.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-doc-updater.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/daily-experiment-report.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-fact.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/daily-file-diet.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/daily-firewall-report.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-formal-spec-verifier.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-function-namer.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/daily-geo-optimizer.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/daily-hippo-learn.lock.yml

Large diffs are not rendered by default.

40 changes: 20 additions & 20 deletions .github/workflows/daily-issues-report.lock.yml

Large diffs are not rendered by default.

24 changes: 12 additions & 12 deletions .github/workflows/daily-malicious-code-scan.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/daily-max-ai-credits-test.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/daily-mcp-concurrency-analysis.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/daily-model-inventory.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/daily-multi-device-docs-tester.lock.yml

Large diffs are not rendered by default.

40 changes: 20 additions & 20 deletions .github/workflows/daily-news.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/daily-observability-report.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-performance-summary.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/daily-regulatory.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/daily-reliability-review.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-rendering-scripts-verifier.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-repo-chronicle.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/daily-safe-output-integrator.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-safe-output-optimizer.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/daily-safe-outputs-conformance.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/daily-safeoutputs-git-simulator.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/daily-secrets-analysis.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-security-observability.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-security-red-team.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/daily-semgrep-scan.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/daily-sentrux-report.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/daily-skill-optimizer.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/daily-spdd-spec-planner.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/daily-syntax-error-quality.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/daily-team-evolution-insights.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/daily-team-status.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/daily-testify-uber-super-expert.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/daily-token-consumption-report.lock.yml

Large diffs are not rendered by default.

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/daily-workflow-updater.lock.yml

Large diffs are not rendered by default.

40 changes: 20 additions & 20 deletions .github/workflows/dataflow-pr-discussion-dataset.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/dead-code-remover.lock.yml

Large diffs are not rendered by default.

40 changes: 20 additions & 20 deletions .github/workflows/deep-report.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/delight.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/dependabot-burner.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/dependabot-campaign.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/dependabot-go-checker.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/dependabot-repair.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/dependabot-worker.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/deployment-incident-monitor.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/design-decision-gate.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/designer-drift-audit.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/dev-hawk.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/dev.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/developer-docs-consolidator.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/dictation-prompt.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/discussion-task-miner.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/docs-noob-tester.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/draft-pr-cleanup.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/duplicate-code-detector.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/example-failure-category-filter.lock.yml

Large diffs are not rendered by default.

24 changes: 12 additions & 12 deletions .github/workflows/example-permissions-warning.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/example-workflow-analyzer.lock.yml

Large diffs are not rendered by default.

40 changes: 20 additions & 20 deletions .github/workflows/firewall-escape.lock.yml

Large diffs are not rendered by default.

24 changes: 12 additions & 12 deletions .github/workflows/firewall.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/functional-pragmatist.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/github-mcp-structural-analysis.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/github-mcp-tools-report.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/github-remote-mcp-auth-test.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/glossary-maintainer.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/go-fan.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/go-logger.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/go-pattern-detector.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/gpclean.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/grumpy-reviewer.lock.yml

Large diffs are not rendered by default.

24 changes: 12 additions & 12 deletions .github/workflows/hippo-embed.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/hourly-ci-cleaner.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/instructions-janitor.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/issue-arborist.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/issue-monster.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/issue-triage-agent.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/jsweep.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/layout-spec-maintainer.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/lint-monster.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/linter-miner.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/lockfile-stats.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/mattpocock-skills-reviewer.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/mcp-inspector.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/mergefest.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/metrics-collector.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/necromancer.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/notion-issue-summary.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/objective-impact-report.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/org-health-report.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/outcome-collector.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/pdf-summary.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/plan.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/poem-bot.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/portfolio-analyst.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/pr-code-quality-reviewer.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/pr-description-caveman.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/pr-nitpick-reviewer.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/pr-sous-chef.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/pr-triage-agent.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/prompt-clustering-analysis.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/python-data-charts.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/q.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/refactoring-cadence.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/refiner.lock.yml

Large diffs are not rendered by default.

26 changes: 13 additions & 13 deletions .github/workflows/release.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/repo-audit-analyzer.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/repo-tree-map.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/repository-quality-improver.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/research.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/ruflo-backed-task.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/safe-output-health.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/schema-consistency-checker.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/schema-feature-coverage.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/scout.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/security-compliance.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/security-review.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/semantic-function-refactor.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/sergo.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/slide-deck-maintainer.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/smoke-agent-all-merged.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/smoke-agent-all-none.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/smoke-agent-public-approved.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/smoke-agent-public-none.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/smoke-agent-scoped-approved.lock.yml

Large diffs are not rendered by default.

22 changes: 11 additions & 11 deletions .github/workflows/smoke-antigravity.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/smoke-call-workflow.lock.yml

Large diffs are not rendered by default.

28 changes: 14 additions & 14 deletions .github/workflows/smoke-ci.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/smoke-claude.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/smoke-codex.lock.yml

Large diffs are not rendered by default.

40 changes: 20 additions & 20 deletions .github/workflows/smoke-copilot-aoai-apikey.lock.yml

Large diffs are not rendered by default.

40 changes: 20 additions & 20 deletions .github/workflows/smoke-copilot-aoai-entra.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/smoke-copilot-arm.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/smoke-copilot-sdk.lock.yml

Large diffs are not rendered by default.

40 changes: 20 additions & 20 deletions .github/workflows/smoke-copilot.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/smoke-create-cross-repo-pr.lock.yml

Large diffs are not rendered by default.

20 changes: 10 additions & 10 deletions .github/workflows/smoke-crush.lock.yml

Large diffs are not rendered by default.

22 changes: 11 additions & 11 deletions .github/workflows/smoke-gemini.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/smoke-multi-pr.lock.yml

Large diffs are not rendered by default.

20 changes: 10 additions & 10 deletions .github/workflows/smoke-opencode.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/smoke-otel-backends.lock.yml

Large diffs are not rendered by default.

22 changes: 11 additions & 11 deletions .github/workflows/smoke-pi.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/smoke-project.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/smoke-service-ports.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/smoke-temporary-id.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/smoke-test-tools.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/smoke-update-cross-repo-pr.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/smoke-workflow-call-with-inputs.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/smoke-workflow-call.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/spec-enforcer.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/spec-extractor.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/spec-librarian.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/stale-pr-cleanup.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/stale-repo-identifier.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/static-analysis-report.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/step-name-alignment.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/sub-issue-closer.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/super-linter.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/technical-doc-writer.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/terminal-stylist.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/test-create-pr-error-handling.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/test-dispatcher.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/test-project-url-default.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/test-quality-sentinel.lock.yml

Large diffs are not rendered by default.

24 changes: 12 additions & 12 deletions .github/workflows/test-workflow.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/tidy.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/typist.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/ubuntu-image-analyzer.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/uk-ai-operational-resilience.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/unbloat-docs.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/update-astro.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/video-analyzer.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/visual-regression-checker.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/weekly-blog-post-writer.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/weekly-editors-health-check.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/weekly-issue-summary.lock.yml

Large diffs are not rendered by default.

34 changes: 17 additions & 17 deletions .github/workflows/weekly-safe-outputs-spec-review.lock.yml

Large diffs are not rendered by default.

38 changes: 19 additions & 19 deletions .github/workflows/workflow-generator.lock.yml

Large diffs are not rendered by default.

36 changes: 18 additions & 18 deletions .github/workflows/workflow-health-manager.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/workflow-normalizer.lock.yml

Large diffs are not rendered by default.

32 changes: 16 additions & 16 deletions .github/workflows/workflow-skill-extractor.lock.yml

Large diffs are not rendered by default.

6 changes: 6 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -504,6 +504,12 @@ MCP Gateway v0.1.5 introduces stricter MCP server validation:
- Review and update MCP server definitions for the new requirements
- Run `gh aw compile` to detect and fix invalid configurations before upgrading

### Bug Fixes

#### Bump the default gh-aw-firewall version to v0.27.7 and sync the embedded AWF config schema.

This updates `DefaultFirewallVersion`, refreshes the embedded AWF schema for the new terminal-cap HTTP 403 behavior and `maxCacheMisses` support, and regenerates pinned workflow artifacts.

## v0.35.1 - 2026-01-06

Maintenance release with dependency updates and minor improvements.
Expand Down
2 changes: 1 addition & 1 deletion pkg/constants/version_constants.go
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,7 @@ const DefaultGitHubMCPServerVersion Version = "v1.3.0"
//
// The first recompile regenerates all lock files using the new version; the second recompile
// refreshes the container SHA pins that were resolved during the first pass.
const DefaultFirewallVersion Version = "v0.27.6"
const DefaultFirewallVersion Version = "v0.27.7"

ghost Jun 19, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[/zoom-out] Container SHA pins appear to be missing from all regenerated lock files — this reduces supply chain security and reproducibility.

The comment above this constant says two recompile passes are needed (make build && make recompile && make recompile) with the second pass resolving per-component SHA digests. The generated lock files only carry 0.27.7 tags without @sha256: pins (previous v0.27.6 lock files had agent=sha256:5b778c... etc. embedded in imageTag). If v0.27.7 digests are not yet resolvable by the toolchain, please note that in the PR description so reviewers know this is intentional rather than a missed step.

💡 What the diff shows

Before (v0.27.6):

# ghcr.io/github/gh-aw-firewall/agent:0.27.6@sha256:5b778c712a25...
"imageTag":"0.27.6,squid=sha256:...,agent=sha256:..."

After (v0.27.7):

# ghcr.io/github/gh-aw-firewall/agent:0.27.7
"imageTag":"0.27.7"

Docker tags are mutable; without SHA pins, a compromised or accidentally overwritten tag could silently run different code.


// AWFExcludeEnvMinVersion is the minimum AWF version that supports the --exclude-env flag.
// Workflows pinning an older AWF version must not emit --exclude-env flags or the run will fail.
Expand Down
5 changes: 5 additions & 0 deletions pkg/workflow/awf_config_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -993,6 +993,11 @@ func TestValidateAWFConfigJSON_AllowsTemplatableModelFallbackEnabled(t *testing.
require.NoError(t, err, "modelFallback.enabled expressions should pass compile-time schema validation")
}

func TestValidateAWFConfigJSON_AllowsMaxCacheMisses(t *testing.T) {
err := validateAWFConfigJSON(`{"apiProxy":{"enabled":true,"maxCacheMisses":3}}`)

ghost Jun 19, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Test covers only one happy-path for maxCacheMisses; minimum boundary and all other new schema fields are untested.

💡 Suggested additions

The schema declares "minimum": 1 for maxCacheMisses but there is no test asserting that maxCacheMisses: 0 is rejected:

func TestValidateAWFConfigJSON_RejectsMaxCacheMissesZero(t *testing.T) {
    err := validateAWFConfigJSON(`{"apiProxy":{"enabled":true,"maxCacheMisses":0}}`)
    require.Error(t, err, "maxCacheMisses of 0 should fail schema validation (minimum: 1)")
}

This PR also adds allowedModels, disallowedModels, diagnostics, and platform to the schema but adds zero tests for any of them. At minimum the happy-path acceptance tests are easy to add and would catch a future regression where these fields are accidentally removed or renamed in the embedded schema.

require.NoError(t, err, "maxCacheMisses should pass compile-time schema validation")
}

ghost Jun 19, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[/tdd] Happy path only — the minimum: 1 constraint on maxCacheMisses is not verified by a rejection test.

Adding a test that confirms maxCacheMisses: 0 is rejected by the schema would guard against the constraint silently disappearing in a future schema refresh.

💡 Suggested test
func TestValidateAWFConfigJSON_RejectsMaxCacheMissesZero(t *testing.T) {
	err := validateAWFConfigJSON(`{"apiProxy":{"enabled":true,"maxCacheMisses":0}}`)
	require.Error(t, err, "maxCacheMisses: 0 should fail schema validation (minimum: 1)")
}

This follows the pattern used by other schema-constraint tests in this file.

ghost Jun 19, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[/tdd] Three new schema fields (allowedModels, disallowedModels, diagnostics) have no test coverage at all.

A future schema refresh could drop or change these fields and tests would not catch it. Given the existing pattern in this file, adding at least acceptance tests for each field would be low-effort.

💡 Suggested additions
func TestValidateAWFConfigJSON_AllowsAllowedModels(t *testing.T) {
	err := validateAWFConfigJSON(`{"apiProxy":{"enabled":true,"allowedModels":["*sonnet*"]}}`)
	require.NoError(t, err, "allowedModels should pass compile-time schema validation")
}

func TestValidateAWFConfigJSON_AllowsDisallowedModels(t *testing.T) {
	err := validateAWFConfigJSON(`{"apiProxy":{"enabled":true,"disallowedModels":["*opus*"]}}`)
	require.NoError(t, err, "disallowedModels should pass compile-time schema validation")
}

func TestValidateAWFConfigJSON_AllowsDiagnosticsCaptureBlockedRequests(t *testing.T) {
	err := validateAWFConfigJSON(`{"apiProxy":{"enabled":true,"diagnostics":{"captureBlockedRequests":"summary"}}}`)
	require.NoError(t, err, "diagnostics.captureBlockedRequests should pass compile-time schema validation")
}


// TestBuildAWFConfigJSON_ValidateFlag verifies that schema validation runs when
// WorkflowData.ValidateAWFConfig is true (--validate mode) and is skipped otherwise.
func TestBuildAWFConfigJSON_ValidateFlag(t *testing.T) {
Expand Down
69 changes: 63 additions & 6 deletions pkg/workflow/schemas/awf-config.schema.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://github.com/github/gh-aw-firewall/releases/download/v0.27.0/awf-config.schema.json",
"$id": "https://raw.githubusercontent.com/github/gh-aw-firewall/main/docs/awf-config.schema.json",

ghost Jun 19, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[/zoom-out] The schema $id changed from a pinned release URL to a floating main branch reference — this decouples the schema identity from the versioned release.

Previously it was https://github.com/github/gh-aw-firewall/releases/download/v0.27.0/awf-config.schema.json (pinned). Now it is https://raw.githubusercontent.com/github/gh-aw-firewall/main/docs/awf-config.schema.json (floating). The $id is the canonical URI for this schema; using main means two different AWF releases will share the same $id, which can confuse validators and tooling that cache by URI.

💡 Suggestion

Consider using the v0.27.7 release URL instead:

"$id": "https://github.com/github/gh-aw-firewall/releases/download/v0.27.7/awf-config.schema.json"

If upstream deliberately changed to a floating $id, consider whether gh-aw should rewrite this field at embed-time to the pinned version URL.

ghost Jun 19, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Schema $id now points to the mutable main branch, creating an identity mismatch with generated configs.

💡 Details and suggested fix

awf_config.go (line 96) registers the embedded schema under the versioned release URL:

schemaURL := fmt.Sprintf("https://github.com/github/gh-aw-firewall/releases/download/%s/awf-config.schema.json", constants.DefaultFirewallVersion)
loader.AddResource(schemaURL, schemaDoc)

Generated AWF configs will therefore emit $schema pointing to the versioned release URL, but the embedded schema now declares $id pointing to the mutable main branch. These two URLs disagree.

Consequences:

  1. AWF runtime — if the firewall validates incoming configs against the $schema URL, it may fetch a different schema than the embedded bytes.
  2. IDE / external tooling — tools that resolve $id (e.g., JSON Language Server) will silently fetch the live main schema instead of the v0.27.7 snapshot, giving permanently mismatched autocomplete/validation once upstream drifts.
  3. Reproducibility — the main URL is mutable; the schema identity will diverge from the embedded bytes on every future upstream commit.

Suggested fix: Keep the $id versioned, matching the URL that awf_config.go already uses for schema registration:

"$id": "https://github.com/github/gh-aw-firewall/releases/download/v0.27.7/awf-config.schema.json"

Or update awf_config.go to register the schema under its actual $id so the two stay in sync.

"title": "AWF Configuration",
"description": "JSON/YAML configuration for awf CLI. CLI flags override config file values. See https://github.com/github/gh-aw-firewall for documentation.",
"type": "object",
Expand Down Expand Up @@ -53,7 +53,7 @@
},
"enableTokenSteering": {
"type": "boolean",
"description": "Enable AI Credits budget steering. When true, the proxy injects budget-warning system messages at 80%, 90%, 95%, and 99% usage to nudge the agent to wrap up. Requires maxAiCredits. Default: false."
"description": "Enable effective token budget steering. When true, the proxy injects budget-warning system messages at 80%, 90%, 95%, and 99% usage to nudge the agent to wrap up. Requires maxEffectiveTokens. Default: false."

ghost Jun 19, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

enableTokenSteering silently changes its prerequisite from maxAiCredits to maxEffectiveTokens with no migration guidance.

💡 Details

The description changed from:

Requires maxAiCredits. Default: false.

To:

Requires maxEffectiveTokens. Default: false.

Any user who upgraded to v0.27.7 with a config like:

{ "apiProxy": { "enableTokenSteering": true, "maxAiCredits": 500 } }

will find that token steering silently stops working (or behaves differently) because the upstream firewall now keys off maxEffectiveTokens rather than maxAiCredits. There is no error, no warning, just different runtime behavior.

This needs an explicit migration note in the CHANGELOG (or at minimum in the unreleased section) along the lines of:

⚠️ If you use apiProxy.enableTokenSteering, replace maxAiCredits with maxEffectiveTokens to retain budget-steering behaviour in v0.27.7.

},
"anthropicAutoCache": {
"type": "boolean",
Expand All @@ -67,12 +67,12 @@
"maxEffectiveTokens": {
"type": "integer",
"minimum": 1,
"description": "Maximum cumulative effective tokens allowed for a run. When reached, the API proxy rejects subsequent requests with HTTP 429 and error type 'effective_tokens_limit_exceeded'. Tokens are weighted: input ×1, cache-read ×0.1, output ×4, reasoning ×4. See spec §10."
"description": "Maximum cumulative effective tokens allowed for a run. When reached, the API proxy rejects subsequent requests with HTTP 403 and error type 'effective_tokens_limit_exceeded'. Tokens are weighted: input ×1, cache-read ×0.1, output ×4, reasoning ×4. See spec §10."

ghost Jun 19, 2026

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Breaking behavioral change: limit-exceeded responses moved from HTTP 429 (retriable) to HTTP 403 (non-retriable) — not flagged as breaking in the CHANGELOG.

💡 Details

Three guards changed their documented error status code from 429 Too Many Requests to 403 Forbidden in this diff: maxEffectiveTokens, maxAiCredits, and maxTurns (and the new maxCacheMisses uses 403 from the start).

429 and 403 carry fundamentally different retry semantics:

  • 429 — standard "rate limited, back off and retry" signal. Clients, CI wrappers, and SDKs with retry logic will automatically retry these.
  • 403 — "forbidden, do not retry". Those same clients will now treat a cap hit as a hard auth/permission failure and stop immediately.

Real-world impact:

  • Any CI wrapper or script that retries on 429 will now silently swallow the error on 403 instead of retrying, breaking runs that previously recovered.
  • Monitoring/alerting rules keyed on 429 to detect cap hits will stop firing.
  • SDK-level retry middleware will interpret the cap hit as a permanent auth failure rather than a transient limit.

The CHANGELOG entry mentions "HTTP 403 behavior" but does not call this out as a breaking change for consumers that differentiate these status codes. The unreleased section should include an explicit migration note for anyone with retry or monitoring logic that keys on HTTP 429 for AWF-proxied requests.

},
"maxAiCredits": {
"type": "number",
"exclusiveMinimum": 0,
"description": "Maximum cumulative AI credits allowed for a run. When reached, the API proxy rejects subsequent requests with HTTP 429 and error type 'ai_credits_limit_exceeded'. AWF also enforces a non-overridable hard cap of 10,000 AI credits; values above 10,000 are effectively clamped."
"description": "Maximum cumulative AI credits allowed for a run. When reached, the API proxy rejects subsequent requests with HTTP 403 and error type 'ai_credits_limit_exceeded'. AWF also enforces a non-overridable hard cap of 10,000 AI credits; values above 10,000 are effectively clamped."
},
"defaultAiCreditsPricing": {
"type": "object",
Expand Down Expand Up @@ -104,7 +104,7 @@
},
"modelMultipliers": {
"type": "object",
"description": "Per-model cost multipliers. Each model's weighted tokens are multiplied by this value before accumulation. Unlisted models use defaultModelMultiplier when set, otherwise the highest configured multiplier. See spec §10.2.",
"description": "Per-model multipliers for effective token accounting. Each model's weighted tokens are multiplied by this value before accumulation. Unlisted models use defaultModelMultiplier when set, otherwise the highest configured multiplier. See spec §10.2.",
"additionalProperties": {
"type": "number",
"exclusiveMinimum": 0
Expand All @@ -123,7 +123,7 @@
"maxTurns": {
"type": "integer",
"minimum": 1,
"description": "Maximum number of LLM invocations allowed for a run. When reached, the API proxy rejects subsequent requests with HTTP 429 and error type 'max_runs_exceeded'. See spec §11."
"description": "Maximum number of LLM invocations allowed for a run. When reached, the API proxy rejects subsequent requests with HTTP 403 and error type 'max_runs_exceeded'. See spec §11."
},
"maxRuns": {
"type": "integer",
Expand All @@ -135,6 +135,11 @@
"minimum": 1,
"description": "Maximum number of upstream permission-denied (401/403) responses allowed per run. When reached, the API proxy rejects all subsequent requests with HTTP 403 and error type 'permission_denied_limit_exceeded', stopping the run to avoid wasting tokens on misconfigured or missing API credentials. When unset, the guard is disabled."
},
"maxCacheMisses": {
"type": "integer",
"minimum": 1,
"description": "Maximum number of consecutive cache misses allowed per run. A miss is counted only for successful responses with non-zero input_tokens and zero cache_read_tokens. Responses with cache_read_tokens > 0 reset the streak. When reached, the API proxy rejects subsequent requests with HTTP 403 and error type 'max_cache_misses_exceeded'."
},
"requestedModel": {
"type": "string",
"description": "Expected model name for pre-startup validation. When set, the API proxy validates at startup that this model is available in at least one provider's model catalogue. Emits a clear diagnostic if the model is retired, restricted, or misspelled. Does not block startup."
Expand Down Expand Up @@ -214,6 +219,20 @@
}
}
},
"allowedModels": {
"type": "array",
"description": "Allowlist of permitted model names (glob patterns). When set, only models matching at least one pattern are permitted. Uses case-insensitive glob matching with * as a wildcard. Evaluated after disallowedModels — a model in the denylist is always rejected even if it matches the allowlist. Examples: [\"*sonnet*\", \"*haiku*\"].",
"items": {
"type": "string"
}
},
"disallowedModels": {
"type": "array",
"description": "Denylist of prohibited model names (glob patterns). Models matching any pattern are rejected with HTTP 403 regardless of the allowedModels allowlist. Uses case-insensitive glob matching with * as a wildcard. Examples: [\"*opus*\", \"gpt-5*\"].",
"items": {
"type": "string"
}
},
"auth": {
"type": "object",
"description": "Authentication configuration for the API proxy sidecar. Enables OIDC-based credential exchange (e.g., GitHub OIDC → Azure AD, AWS STS, GCP Workload Identity, or Anthropic Workload Identity Federation). See docs/awf-config-spec.md §9.5.",
Expand Down Expand Up @@ -360,6 +379,32 @@
"default": "/var/log/api-proxy"
}
}
},
"diagnostics": {
"type": "object",
"description": "Opt-in diagnostics for blocked LLM requests. Writes body-shape records to blocked-request-diag.jsonl when a guard hard-rails a request.",
"additionalProperties": false,
"properties": {
"captureBlockedRequests": {
"description": "Enable capture of body-shape diagnostics for guard-blocked requests. 'summary' captures counts/sizes/hashes only (no content). 'redacted' adds first 200 chars per message. 'full' captures the entire body up to maxCapturedBytes. Maps to AWF_CAPTURE_BLOCKED_LLM_REQUESTS.",
"oneOf": [
{
"type": "boolean"
},
{
"type": "string",
"enum": ["summary", "redacted", "full"]
}
],
"default": false
},
"maxCapturedBytes": {
"type": "integer",
"description": "Maximum body bytes to include in a single 'full'-mode blocked-request-diag record. Maps to AWF_MAX_BLOCKED_CAPTURE_BYTES.",
"minimum": 1,
"default": 250000
}
}
}
}
},
Expand Down Expand Up @@ -634,6 +679,18 @@
"description": "Maximum number of bytes transferred per minute."
}
}
},
"platform": {
"type": "object",
"description": "GitHub platform deployment type. Explicitly declares the environment so AWF can apply correct auth behavior (e.g. token vs Bearer prefix) without relying on heuristic detection.",
"additionalProperties": false,
"properties": {
"type": {
"type": "string",
"enum": ["github.com", "ghes", "ghec", "ghec-self-hosted"],
"description": "The GitHub deployment type. 'github.com' = GitHub.com (default), 'ghes' = GitHub Enterprise Server (on-premises), 'ghec' = GitHub Enterprise Cloud (*.ghe.com tenants), 'ghec-self-hosted' = GHEC with self-hosted runners."
}
}
}
},
"$defs": {
Expand Down
Loading
Loading