Bump gh-aw-firewall (AWF) to v0.28.17 - #60945
Conversation
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
There was a problem hiding this comment.
🟡 Changes recommended
It silently upgrades unrelated gh-aw-node and xberg container images without corresponding provenance or review.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Bumps bundled gh-aw-firewall from v0.28.16 to v0.28.17 and regenerates its pins and workflows.
Changes:
- Updates the default AWF version and four firewall image digests.
- Synchronizes pin data and regenerates 299 workflow lock files.
- Adds a patch changeset.
- Also refreshes unrelated gh-aw-node and xberg image digests, which should be separated or explicitly reviewed.
File summaries
| File | Description |
|---|---|
.changeset/bump-awf-v0-28-17.md |
Documents the AWF bump. |
.github/aw/actions-lock.json |
Adds AWF pins; also changes unrelated image pins. |
pkg/actionpins/data/action_pins.json |
Synchronizes image pins. |
pkg/constants/version_constants.go |
Sets AWF v0.28.17 as default. |
pkg/workflow/data/action_pins.json |
Synchronizes embedded workflow pins. |
.github/workflows/*.lock.yml (299 files) |
Regenerates workflows with AWF v0.28.17 and refreshed container digests. |
Review details
- Files reviewed: 21/304 changed files
- Comments generated: 2
- Review effort level: Balanced
|
/smoke-copilot |
|
📰 BREAKING: Smoke Copilot is now investigating this issue comment. Sources say the story is developing... |
|
✅ Ponytail Reviewer completed successfully! Cannot run ponytail review: /tmp/gh-aw/agent/pr-diff.patch is empty. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"See Network Configuration for more information.
|
|
🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
|
|
Warning Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding. What happenedThe threat detection engine failed to produce results. Review the workflow run logs for details.
|
|
No ADR enforcement needed: PR does not have the implementation label and has ≤100 new lines of code in business logic directories.
|
|
✅ Test Quality Sentinel completed test quality analysis. Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch PR file list
|
There was a problem hiding this comment.
Skills-Based Review 🧠
Applied /diagnosing-bugs — the change itself (version bump + regenerated lockfiles) is clean and low-risk, but the digest-refresh side effect needs a fix before merge.
📋 Key Themes & Highlights
Key Themes
- Unreviewed scope creep:
ghcr.io/github/gh-aw-nodeandghcr.io/xberg-io/xberg:latest(both unversioned/mutable tags) were silently re-pinned to new digests as a side effect ofpkg/cli/update_container_pins.go'srefreshExisting: truere-resolution, even though this PR is scoped to the four AWF v0.28.17 sidecars. These duplicate two existing unresolved review comments (4010813006,4010813070) — I've left inline comments reinforcing both with a concrete fix. - Core change verified correct: I independently confirmed
DefaultFirewallVersionwent fromv0.28.16→v0.28.17, noAWF*MinVersionconstants needed changes (checked all ~20 constants — none reference v0.28.15–17 features), and the four new firewall sidecar digests (agent/api-proxy/cli-proxy/squid) were added consistently across.github/aw/actions-lock.json,pkg/actionpins/data/action_pins.json, andpkg/workflow/data/action_pins.json. - 299
.lock.ymlregenerations: mechanical, consistent with the pin change — not reviewed line-by-line as generated artifacts.
Positive Highlights
- ✅ Version bump claim (no new CLI flags) verified against the constants file
- ✅ Changeset entry present and correctly scoped
- ✅ All three pin-store copies (actions-lock.json + 2 synced JSON files) stay consistent with each other
@copilot please address the review comments above.
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
github.com
To allow these domains, add them to the network.allowed list in your workflow frontmatter:
network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 102.6 AIC · ⌖ 16.3 AIC · ⊞ 10.4K
Comment /matt to run again
|
Smoke Test Summary — Run 34914998863 PR: "Bump gh-aw-firewall (AWF) to v0.28.17"
Overall: FAIL (4/16 failed) Author: app/copilot-swe-agent · Assignees: lpcox, Copilot Warning Firewall blocked 7 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "host.docker.internal"
- "www.google.com"
- "www.gstatic.com"See Network Configuration for more information.
|
Comment MemoryNote This comment is managed by comment memory.It stores persistent context for this thread in the code block at the top of this comment. Warning Firewall blocked 7 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "host.docker.internal"
- "www.google.com"
- "www.gstatic.com"See Network Configuration for more information.
|
There was a problem hiding this comment.
Smoke test: automated review pass - added inline comments, no blocking issues found.
Warning
Firewall blocked 7 domains
The following domains were blocked by the firewall during workflow execution:
accounts.google.comandroid.clients.google.comclients2.google.comcontentautofill.googleapis.comhost.docker.internalwww.google.comwww.gstatic.com
To allow these domains, add them to the network.allowed list in your workflow frontmatter:
network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "host.docker.internal"
- "www.google.com"
- "www.gstatic.com"See Network Configuration for more information.
📰 BREAKING: Report filed by Smoke Copilot · copilot · auto · 74.5 AIC · ⌖ 3.93 AIC · ⊞ 10.1K
Comment /smoke-copilot to run again
Add label smoke to run again
|
@copilot Please take another pass on this PR and run the
Latest failing workflow feedback: Run: https://github.com/github/gh-aw/actions/runs/34917743100
|
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Scoped cleanup is pushed in |
|
@copilot Please take another pass on this PR and run the Review feedback:
Run: https://github.com/github/gh-aw/actions/runs/34926826647 Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
|
The scope cleanup remains present on |
|
@copilot Please take another pass on this PR and run the The latest author response says the scope cleanup is already present, but the PR is still blocked by stale review state. Review feedback:
Please verify the branch still contains only the AWF bump, refresh the review state, and summarize any blocker that still requires maintainer action. Run: https://github.com/github/gh-aw/actions/runs/34930063094 Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
|
Verified against merge base |
|
@copilot update the PR to bump the firewall version to https://github.com/github/gh-aw-firewall/releases/tag/v0.28.18 and the mcpg version to https://github.com/github/gh-aw-mcpg/releases/tag/v0.4.23 |
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Updated and pushed: |
|
@copilot discard all PR updates to .lock.yml and merge main |
…rewall-to-v02817 # Conflicts: # .github/workflows/agent-performance-analyzer.lock.yml # .github/workflows/agent-persona-explorer.lock.yml # .github/workflows/agentic-token-trend-audit.lock.yml # .github/workflows/blog-auditor.lock.yml # .github/workflows/daily-agentrx-trace-optimizer.lock.yml # .github/workflows/daily-ambient-context-optimizer.lock.yml # .github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml # .github/workflows/daily-news.lock.yml # .github/workflows/dependabot-go-checker.lock.yml # .github/workflows/gpclean.lock.yml # .github/workflows/smoke-gemini.lock.yml # .github/workflows/smoke-temporary-id.lock.yml Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Completed in |
Requested changes were addressed in 0847925; unrelated digest updates were reverted and all associated threads are resolved.
|
🎉 This pull request is included in a new release. Release: |
Bumps the pinned
github/gh-aw-firewallversion fromv0.28.16tov0.28.17and refreshes all generated artifacts to match.Changes
DefaultFirewallVersioninpkg/constants/version_constants.gotov0.28.17. Reviewed the upstream changelog (docs cross-refs, internal Cloud Hypervisor refactors, API proxy audit log/permission fixes) — no new or removed CLI flags, so noAWF*MinVersionconstants needed updating.agent,api-proxy,cli-proxy,squid) at0.28.17and refreshed.github/aw/actions-lock.jsonplus the syncedpkg/actionpins/data/action_pins.json/pkg/workflow/data/action_pins.json..lock.ymlfiles so they embed the new pinned firewall images..changeset/bump-awf-v0-28-17.mddocumenting the bump.Run: https://github.com/github/gh-aw/actions/runs/34926826647
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
github.laiyagushi.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.
Run: https://github.com/github/gh-aw/actions/runs/34930063094
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
github.laiyagushi.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.