Skip to content

Refresh CLI defaults and scanner image pins - #61432

Merged
pelikhan merged 7 commits into
mainfrom
copilot/update-cli-version-checker
Sep 17, 2026
Merged

pelikhan merged 7 commits into
mainfrom
copilot/update-cli-version-checker

Conversation

Copilot AI commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Updates repository-pinned CLI defaults and scanner images to current verified releases. Playwright CLI remains on 0.1.19 until its enforced npm release-age cooldown expires.

  • CLI defaults

    • Claude Code: 2.1.273
    • Copilot CLI: 1.0.85
    • Codex: 0.154.0
    • Synced Copilot compatibility and installer fallback metadata.
  • Scanner images

    ZizmorImage = "ghcr.io/zizmorcore/zizmor:1.30.1@sha256:..."
    SyftImage   = "anchore/syft:v1.51.1@sha256:..."
    GrypeImage  = "anchore/grype:v0.118.0@sha256:..."
  • Pin coverage

    • Updated CLI version expectations, including Copilot CLI.

pr-sous-chef branch refresh requested from https://github.com/github/gh-aw/actions/runs/35170906176

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 38.2 AIC · ⊞ 9.1K · ◷
Comment /souschef to run again


Run: https://github.com/github/gh-aw/actions/runs/35174719104

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 54.4 AIC · ⊞ 9K · ◷
Comment /souschef to run again

Copilot AI and others added 2 commits September 16, 2026 23:44
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Update CLI version for defaults and scanner images Refresh CLI defaults and scanner image pins Sep 16, 2026
Copilot AI requested a review from pelikhan September 16, 2026 23:49
@pelikhan
pelikhan marked this pull request as ready for review September 17, 2026 00:35
Copilot AI balanced review requested due to automatic review settings September 17, 2026 00:35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The release changeset and scanner inventory documentation need updating.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Refreshes pinned CLI defaults and scanner images while keeping Copilot compatibility metadata synchronized.

Changes:

  • Updates Claude Code, Copilot CLI, and Codex defaults.
  • Refreshes Zizmor, Syft, and Grype image pins.
  • Aligns Copilot installer and compatibility fallbacks.
File summaries
File Description
pkg/constants/version_constants.go Updates CLI defaults.
pkg/constants/version_constants_test.go Updates version expectations.
pkg/cli/docker_images.go Refreshes scanner image pins.
actions/setup/sh/install_copilot_cli.sh Updates installer fallback.
.github/aw/compat.json Expands Copilot compatibility.
Review details
  • Files reviewed: 5/5 changed files
  • Comments generated: 2
  • Review effort level: Balanced

Comment thread pkg/cli/docker_images.go
Comment on lines +37 to +38
SyftImage = "anchore/syft:v1.51.1@sha256:95fe0835e5bebc6f8b1f8acef68d47d63d594ef4c0f25c097ff853b23cbac74c"
GrypeImage = "anchore/grype:v0.118.0@sha256:8a93fc48da96bd6ec5981279d099b69de11541dc68fdf222fb9161f8ff284af7"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in 2792f4b by updating pkg/cli/README.md so the scanner inventory documents Grype v0.118.0 and Syft v1.51.1.


// DefaultClaudeCodeVersion is the default version of the Claude Code CLI.
const DefaultClaudeCodeVersion Version = "2.1.266"
const DefaultClaudeCodeVersion Version = "2.1.273"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in 2792f4b by adding .changeset/patch-refresh-cli-defaults-scanner-pins.md covering the CLI default and scanner pin refresh.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

pr-sous-chef
@copilot this PR still needs forward progress before a maintainer can investigate quickly. Please update the release changeset and scanner inventory documentation called out in review, refresh the branch if needed, and then run the pr-finisher skill.

Latest blocking review points:

  • update the release changeset to reflect the CLI default and scanner pin refresh
  • refresh the scanner inventory documentation so it stays in sync with the new pins and defaults

Run URL: https://github.com/github/gh-aw/actions/runs/35170906176

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 38.2 AIC · ⊞ 9.1K · ◷
Comment /souschef to run again

…efresh

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

pr-sous-chef
@copilot this PR still needs forward progress before a maintainer can investigate quickly. Please update the release changeset and scanner inventory documentation called out in review, ...

Added a changeset (.changeset/patch-refresh-cli-defaults-scanner-pins.md) covering the CLI/scanner refresh and updated the scanner inventory in pkg/cli/README.md (Grype v0.118.0, Syft v1.51.1). Lock files were recompiled to reflect the new Codex default version.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot this PR still needs forward progress before a maintainer can investigate quickly. The branch already has follow-up changes for the earlier review, so please request a fresh Copilot review, refresh the branch if needed, and then run the pr-finisher skill.

Previously raised review points that should be re-evaluated:

  • release changeset coverage for the CLI/scanner refresh
  • scanner inventory documentation sync with the new pins/defaults

Run URL: https://github.com/github/gh-aw/actions/runs/35174719104

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 54.4 AIC · ⊞ 9K · ◷
Comment /souschef to run again

Copilot AI commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

@copilot this PR still needs forward progress before a maintainer can investigate quickly. The branch already has follow-up changes for the earlier review, so please request a fresh Copilot review, re...

Branch is refreshed through 454b356, and the prior review points are already addressed in 2792f4b: the changeset was added and the scanner inventory docs now match the updated pins. I ran the pr-finisher pass and local validation (make fmt, make lint, make test-unit, make test, make recompile); no further code changes were needed.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

pr-sous-chef
@copilot this PR looks close, but it still needs a fresh review pass before a maintainer can investigate quickly. The branch already includes follow-up replies for the changeset and scanner-doc comments, so please request a fresh Copilot review, refresh the branch if needed, and then run the pr-finisher skill.

Previously raised review points to re-check:

  • release changeset coverage for the CLI/scanner refresh
  • scanner inventory documentation sync with the updated pins/defaults

Run URL: https://github.com/github/gh-aw/actions/runs/35176271104

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 48.6 AIC · ⊞ 9K · ◷
Comment /souschef to run again

Copilot AI commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

pr-sous-chef
@copilot this PR looks close, but it still needs a fresh review pass before a maintainer can investigate quickly. The branch already includes follow-up replies for the changeset and sca...

Branch is already refreshed to current main (290730b, included by 454b356), and the follow-up review replies are in place for both original threads. I reran the pr-finisher validation pass: make fmt, make lint, make test-unit, make test, and make recompile all passed; recompile only produced transient local pin fallback diffs, which I discarded to keep the branch unchanged. I also attempted the available fresh validation hook, but it skipped because there were no new local changes to review.

@pelikhan
pelikhan merged commit c054206 into main Sep 17, 2026
2 checks passed
@pelikhan
pelikhan deleted the copilot/update-cli-version-checker branch September 17, 2026 06:46
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.89.17

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[ca] CLI version checker: detected upstream updates for CLI defaults and scanner images

4 participants