Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 5 additions & 1 deletion .github/aw/create-agentic-workflow.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ Load these topic files only when relevant:
- [deployment-status.md](deployment-status.md) for external deployment monitoring
- [charts.md](charts.md) for chart-generation workflows
- [report.md](report.md) for reporting output structure and recurring report lifecycle
- [release-workflow.md](release-workflow.md) for release workflows that build, test, publish a GitHub release, and generate release highlights
- [release-workflow.md](release-workflow.md) whenever a workflow creates or updates release notes, including workflows that also build, test, or publish a GitHub release
- [linter-workflows.md](linter-workflows.md) for mining, refining, or applying custom linter rules
- [agent-runtime-instructions.md](agent-runtime-instructions.md) when choosing or debugging Docker, gVisor, Docker sbx, ARC DinD, self-hosted runners, or `sandbox.agent.runtime-install`
- [skills.md](skills.md) when the user asks for specific skills or agent plugins
Expand All @@ -37,6 +37,10 @@ Load these topic files only when relevant:

When the user requests specific skills or agent plugins, declare them in the built-in top-level `skills:` and `plugins:` frontmatter fields — gh-aw installs them before the agent runs. Never generate on-the-fly installation (`steps:` running `gh skill install`, `copilot plugin install`, `npx`, `curl`, or `git clone`) and never instruct the agent to install a skill or plugin from the prompt body. See [skills.md](skills.md).

## Release Notes

Any agent-generated release notes or release-description changes must use the `update-release` safe output. Keep the agent job read-only; never grant it write permissions or direct it to mutate a release with `gh`, the GitHub API, or a GitHub write tool.

## Modes

### Interactive mode
Expand Down
5 changes: 4 additions & 1 deletion .github/aw/release-workflow.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,9 @@ Use this guidance when the user asks to create a workflow that:
- Builds, tests, and publishes a GitHub release
- Generates or prepends release highlights / changelog summaries to the release description

> [!IMPORTANT]
> Agent-generated release notes and all other agent-driven release-description changes must use the `update-release` safe output. The agent must not mutate releases directly with `gh`, the GitHub API, or a GitHub write tool.
Comment on lines +12 to +13

## Pattern Overview

A release workflow follows the **Classic + Agent** hybrid structure:
Expand Down Expand Up @@ -226,7 +229,7 @@ Do not replace the auto-generated notes — prepend only.

## Key Rules

- **Agent job stays read-only** — all writes route through `update-release`
- **Agent job stays read-only** — all release-note and release-description writes must route through `update-release`; never use direct `gh`, API, or GitHub write-tool mutations
- **Use `operation: "prepend"`** so highlights appear before the auto-generated GitHub notes; never `replace`
- **The `release` job must output `release_id`** — the agent needs the database ID to reference the correct release
- **Pre-fetch all data in `steps:`** before the agent runs; write compact JSON to `/tmp/gh-aw/agent/release-data/`
Expand Down
2 changes: 1 addition & 1 deletion .github/aw/safe-outputs-automation.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ description: Safe-output reference for workflow dispatch, code scanning, checks,
target-repo: "owner/repo" # Optional: cross-repository
```

- `update-release:` - Update GitHub release descriptions
- `update-release:` - Update GitHub release descriptions. Agent-generated release notes and release-description changes must use this safe output; never perform those mutations directly with `gh`, the GitHub API, or a GitHub write tool.

```yaml
safe-outputs:
Expand Down
2 changes: 2 additions & 0 deletions .github/aw/update-agentic-workflow.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,7 @@ Load these additional files only when relevant:
- [visual-regression.md](visual-regression.md)
- [serena-tool.md](serena-tool.md)
- [linter-workflows.md](linter-workflows.md)
- [release-workflow.md](release-workflow.md) whenever a workflow creates or updates release notes
- [agent-runtime-instructions.md](agent-runtime-instructions.md) for changes involving Docker, gVisor, Docker sbx, ARC DinD, self-hosted runners, or `sandbox.agent.runtime-install`
- [skills.md](skills.md) when the user asks to add specific skills or agent plugins

Expand Down Expand Up @@ -50,6 +51,7 @@ Use [workflow-editing.md](workflow-editing.md) as the source of truth for when r
- when an implementation-only change selects a different architecture, revalidate activation conditions, evidence window, deduplication or previous-result strategy, no-op behavior, and evals so event-specific rules do not survive an incompatible redesign
- when targeting the Copilot coding agent, recommend `permissions: { copilot-requests: write }` for Copilot authentication
- prefer `toolsets:` for GitHub tools
- require `update-release` for agent-generated release notes or release-description changes; never use direct `gh`, API, or GitHub write-tool mutations from the agent
- when the user asks for specific skills or agent plugins, add them to the top-level `skills:` / `plugins:` frontmatter fields; never add on-the-fly install steps or prompt instructions to install them at run time (see [skills.md](skills.md))

See [workflow-constraints.md](workflow-constraints.md) for the read-only security posture (keep the agent job read-only, route writes through `safe-outputs:`).
Expand Down
2 changes: 1 addition & 1 deletion .github/aw/workflow-patterns.md
Original file line number Diff line number Diff line change
Expand Up @@ -276,7 +276,7 @@ For workflows that build, test, publish a GitHub release, and generate release h
- structure: **Classic + Agent** hybrid — all build/test/release jobs are standard GitHub Actions jobs; the agent job runs last and only updates the release description
- classic jobs: `config` (compute semver), `build` (compile + upload artifact), `test`, `release` (create prerelease with `--generate-notes --latest=false`); output `release_id` from the release job
- agent job: depends on `release` job; pre-fetches merged PRs and changelog in `steps:`; uses `tools: cli-proxy: true`; writes highlights via `update-release` with `operation: prepend`
- safe output: `update-release` with `threat-detection: false` (release bodies contain code snippets)
- safe output: agent-generated release notes and release-description changes must use `update-release`; never mutate releases directly with `gh`, the GitHub API, or a GitHub write tool; set `threat-detection: false` because release bodies can contain code snippets
- permissions: global `contents: read`; per-job `contents: write` only on jobs that push tags or create releases

See [release-workflow.md](release-workflow.md) for the full pattern, frontmatter template, job skeletons, and reference implementation pointer.
Expand Down