chore: sync workflow templates - #614
Conversation
Automated sync from stranske/Workflows Template hash: e8a3a32a3996 Changes synced from sync-manifest.yml
🤖 Keepalive Loop StatusPR #614 | Agent: Codex | Iteration 0/5 Current State
🔍 Failure Classification| Error type | infrastructure | |
Keepalive Work Log (click to expand)
|
There was a problem hiding this comment.
Pull request overview
Syncs workflow templates from stranske/Workflows, expanding weekly metrics collection/telemetry and adding richer machine-readable contracts for downstream monitoring.
Changes:
- Extend weekly metrics artifact selection + add an explicit artifact download manifest (JSON + markdown) and publish a new aggregated JSON contract.
- Add verifier follow-up ledger telemetry and enrich terminal-disposition coverage with verifier model compatibility checks.
- Improve keepalive task counting by filtering out status/placeholder checklist items; enhance PR body preamble behavior for campaign issues.
Reviewed changes
Copilot reviewed 14 out of 14 changed files in this pull request and generated 4 comments.
Show a summary per file
| File | Description |
|---|---|
scripts/aggregate_agent_metrics.py |
Adds artifact/source attribution, parse error detail reporting, verifier follow-up ledger summarization, and emits a JSON summary contract (plus optional artifact download manifest ingestion). |
.github/workflows/agents-weekly-metrics.yml |
Generates and updates an artifact download manifest while downloading/unzipping metrics, and uploads the new JSON summary artifact. |
.github/workflows/agents-verify-to-new-pr.yml |
Adds verifier follow-up ledger NDJSON emission and uploads it alongside terminal disposition artifacts; updates agent selection defaults. |
.github/workflows/agents-bot-comment-handler.yml |
Adds skip reason outputs and writes/uploads a wrapper terminal disposition record for observability. |
.github/workflows/agents-81-gate-followups.yml |
Uses compact JSON output for gate follow-up metrics (jq -cn). |
.github/scripts/weekly_metrics_download_manifest.js |
New script to initialize/record/finalize a machine-readable artifact download/unzip manifest and optional markdown summary. |
.github/scripts/weekly_metrics_artifacts.js |
Enhances selection report with priority family status metadata and latest-candidate details. |
.github/scripts/terminal_disposition_coverage.js |
Adds verifier model compatibility checks and richer artifact-selection normalization/markdown reporting. |
.github/scripts/terminal_disposition.js |
Adds verifier follow-up ledger/policy normalization helpers and enriches terminal disposition records with model metadata fields. |
.github/scripts/keepalive_loop.js |
Filters non-actionable checklist items from task/acceptance counting and related summary logic. |
.github/scripts/coverage_monitor_summary.js |
New script emitting a weekly “coverage monitor” summary contract (JSON + markdown). |
.github/scripts/bot_comment_auth_coverage.js |
Tracks wrapper decisions about whether reusable invocation was expected; surfaces skipped/missing organic requirements in the report/markdown. |
.github/scripts/agents_pr_meta_update_body.js |
Adjusts PR preamble to use campaign-aware “Related to …” vs “Closes …” and adds a hidden meta issue marker. |
.github/actions/setup-api-client/action.yml |
Adds a redacted “setup contract” output describing token/auth/dependency state for diagnostics. |
| - name: Check PR is merged | ||
| id: check-merged | ||
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9 | ||
| uses: actions/github-script@v9 | ||
| with: | ||
| github-token: ${{ github.token }} |
There was a problem hiding this comment.
This workflow switches several GitHub Actions from commit-SHA pinning to mutable version tags (e.g., actions/github-script@v9). Most agents-* workflows in this repo pin these actions to a specific commit (for supply-chain safety and reproducibility), e.g. .github/workflows/agents-weekly-metrics.yml uses actions/github-script@3a2844b7.... Consider reverting to the prior commit-SHA pin (or updating to a specific SHA for v9) instead of the tag.
| - name: Checkout repository | ||
| if: steps.check-merged.outputs.merged == 'true' | ||
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 | ||
| uses: actions/checkout@v6 |
There was a problem hiding this comment.
This step changes actions/checkout from a commit-SHA pin to the mutable @v6 tag. In this repo’s agents-* workflows, actions/checkout is typically pinned (e.g. .github/workflows/agents-weekly-metrics.yml uses actions/checkout@de0fac2e...). Using a tag weakens supply-chain protections and can introduce non-reproducible runs; prefer pinning to a specific commit SHA.
| uses: actions/checkout@v6 | |
| uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 |
| - name: Set up Python | ||
| if: steps.check-merged.outputs.merged == 'true' | ||
| uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6 | ||
| uses: actions/setup-python@v6 |
There was a problem hiding this comment.
This step switches actions/setup-python from a commit-SHA pin to the mutable @v6 tag. For consistency with other agents-* workflows and to avoid supply-chain/reproducibility risk, pin actions/setup-python to a specific commit SHA (as done elsewhere in the repo, e.g. .github/workflows/agents-weekly-metrics.yml).
| uses: actions/setup-python@v6 | |
| uses: actions/setup-python@42375524f58b9b19dbda3c6bfe40cb79e2b1ba88 |
| - name: Upload terminal disposition artifact | ||
| if: always() && steps.check-merged.outputs.merged == 'true' | ||
| uses: actions/upload-artifact@65ecb0ca2d3e252f7b82842cd0489c883189f7d0 # v7 | ||
| uses: actions/upload-artifact@v7 | ||
| with: | ||
| name: verifier-terminal-disposition-${{ github.run_id }} | ||
| path: | | ||
| agent-metrics/verifier-terminal-disposition.ndjson | ||
| agent-metrics/verifier-followup-ledger.ndjson |
There was a problem hiding this comment.
This step switches actions/upload-artifact from a commit-SHA pin to the mutable @v7 tag. To match the pinning approach used throughout the agents-* workflows (and to reduce supply-chain risk), pin to the specific commit SHA for the intended v7 release.
Sync Summary
Files Updated
Files Skipped
Review Checklist
Source: stranske/Workflows
Manifest:
.github/sync-manifest.yml