Skip to content

Bump MCP Gateway to v0.4.25 - #61661

Merged
pelikhan merged 2 commits into
mainfrom
copilot/bump-mcpg-version-0425
Sep 17, 2026
Merged

pelikhan merged 2 commits into
mainfrom
copilot/bump-mcpg-version-0425

Conversation

Copilot AI commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Upgrades the pinned MCP Gateway (gh-aw-mcpg) Docker image from v0.4.23 to v0.4.25.

Version constant

  • DefaultMCPGatewayVersion → v0.4.25 in pkg/constants/version_constants.go, with the matching expectation in version_constants_test.go.

Container pin

  • .github/aw/actions-lock.json container pin replaced with the immutable digest for the new tag, and synced to pkg/actionpins/data/action_pins.json and pkg/workflow/data/action_pins.json:
ghcr.io/github/gh-aw-mcpg:v0.4.25@sha256:9be0a86220e807a0ecc89e53d7453468f7a53fbc6b3d1efd2299025ffe01d086

Regenerated workflows

  • All 299 .lock.yml files recompiled so manifests, download_docker_images.sh arguments, and MCP_GATEWAY_DOCKER_COMMAND reference the new pinned image.

Changeset

  • .changeset/upgrade-gh-aw-mcpg-v0-4-25.md (patch).

Minimum-version gates (MCPGIntegrityReactionsMinVersion, MCPGEnclave*MinVersion, MCPGDynamicRepositoryDelegationMinVersion) are unchanged — no new capability gates in this release.


Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 9.26 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
@lpcox
lpcox marked this pull request as ready for review September 17, 2026 19:25
Copilot AI balanced review requested due to automatic review settings September 17, 2026 19:25

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The update spans 299 regenerated workflow locks, warranting final human review.

Pull request overview

Bumps the MCP Gateway image from v0.4.23 to v0.4.25 with a refreshed immutable digest and regenerated workflow locks.

Changes:

  • Updated version constants and pin data.
  • Regenerated reviewed workflow lockfiles.
  • Added a patch changeset.
File summaries
File Summary
pkg/workflow/data/action_pins.json Updated workflow container pin.
pkg/constants/version_constants.go Bumped default gateway version.
pkg/constants/version_constants_test.go Updated version expectation.
pkg/actionpins/data/action_pins.json Updated embedded container pin.
.github/workflows/windows.lock.yml Regenerated with the new gateway pin.
.github/workflows/smoke-copilot-small.lock.yml Regenerated with the new gateway pin.
.github/workflows/schema-feature-coverage.lock.yml Regenerated with the new gateway pin.
.github/workflows/github-remote-mcp-auth-test.lock.yml Regenerated with the new gateway pin.
.github/workflows/firewall.lock.yml Regenerated with the new gateway pin.
.github/workflows/draft-pr-cleanup.lock.yml Regenerated with the new gateway pin.
.github/workflows/daily-team-status.lock.yml Regenerated with the new gateway pin.
.github/workflows/daily-squid-image-scan.lock.yml Regenerated with the new gateway pin.
.github/workflows/daily-spec-coverage-kiro.lock.yml Regenerated with the new gateway pin.
.github/workflows/daily-schema-audit-cursor.lock.yml Regenerated with the new gateway pin.
.github/workflows/daily-regression-audit-kiro.lock.yml Regenerated with the new gateway pin.
.github/workflows/daily-pr-review-cursor.lock.yml Regenerated with the new gateway pin.
.github/workflows/daily-github-docs-seo-optimizer.lock.yml Regenerated with the new gateway pin.
.github/workflows/daily-community-attribution.lock.yml Regenerated with the new gateway pin.
.github/workflows/copilot-pr-merged-report.lock.yml Regenerated with the new gateway pin.
.github/workflows/codex-github-remote-mcp-test.lock.yml Regenerated with the new gateway pin.
.github/workflows/breaking-change-checker.lock.yml Regenerated with the new gateway pin.
.github/aw/actions-lock.json Updated immutable container digest.
.changeset/upgrade-gh-aw-mcpg-v0-4-25.md Added patch changeset.
Review details
  • Files reviewed: 69/305 changed files
  • Comments generated: 0
  • Review effort level: Lite (auto)

Note

Copilot is running an experiment and ran this review at Lite.


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@github-actions

github-actions Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ PR Code Quality Reviewer failed during code quality review.

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

🔎 Code quality review by PR Code Quality Reviewer

@github-actions

github-actions Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch PR file list

🧪 Test quality analysis by Test Quality Sentinel

@github-actions

github-actions Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

✅ Ponytail Reviewer completed successfully!

Cannot run ponytail review: /tmp/gh-aw/agent/pr-diff.patch is empty (0 bytes), so there is no diff to review.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • ab.chatgpt.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "ab.chatgpt.com"

See Network Configuration for more information.

Generated by Ponytail Reviewer for #61661

@github-actions

github-actions Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

github-actions Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Security scanning failed for Design Decision Gate 🏗️. Review the logs for details.

No ADR enforcement needed: PR does not have the 'implementation' label and has <=100 new lines of code in business logic directories.

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot This PR looks blocked on maintainer follow-up rather than active checks. Please review the current feedback, refresh the branch if needed, and run the pr-finisher skill to move this over the line.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 10.3 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skills-Based Review 🧠

This is a mechanical dependency bump (MCP Gateway v0.4.23 → v0.4.25): version constant, container digest pin (synced across both action_pins.json copies), changeset, and 299 regenerated .lock.yml files. No application logic, control flow, or test-relevant behavior changed, so /diagnosing-bugs, /tdd, and /codebase-design don't surface actionable findings here.

📋 Verification performed
  • DefaultMCPGatewayVersion in pkg/constants/version_constants.go and its test expectation both updated to v0.4.25.
  • Digest sha256:9be0a862... is identical across .github/aw/actions-lock.json, pkg/actionpins/data/action_pins.json, and pkg/workflow/data/action_pins.json.
  • No stale v0.4.23 references remain in any .lock.yml file (checked all 299).
  • Changeset present and correctly scoped as patch.

No blocking issues found.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 39 AIC · ⌖ 14.9 AIC · ⊞ 10.6K
Comment /matt to run again

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

@copilot This PR looks blocked on maintainer follow-up rather than active checks. Please review the current feedback, refresh the branch if needed, and run the pr-finisher skill to move this over th...

Addressed in b3cdf9d: sorted the action lock containers entries in .github/aw/actions-lock.json and the embedded pin data, which fixes the reproduced TestActionsLockJSONFieldsAreSorted/root_actions_lock failure. Local validation passed (make fmt, make lint, make test-unit, make test, make recompile, and final make agent-report-progress).

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot The latest push addressed the previous sous-chef nudge, but this PR still appears blocked on maintainer follow-up. Please review any remaining feedback, refresh the branch if needed, and run the pr-finisher skill to help move it to a maintainer-ready state.

Failed checks to review:

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 10 AIC · ⊞ 9.6K · ◷
Comment /souschef to run again

Copilot AI commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

@copilot The latest push addressed the previous sous-chef nudge, but this PR still appears blocked on maintainer follow-up. Please review any remaining feedback, refresh the branch if needed, and run ...

Ran the pr-finisher pass on the current head b3cdf9d. No review threads remain, the branch is up to date with origin/main, and the working tree is clean. Local validation passed: make fmt, make lint, make test-unit, make test, and make recompile.

The listed Design Decision Gate run is successful on attempt 2. The PR Code Quality Reviewer failure is from the earlier head 04a85d6 and appears stale after b3cdf9d fixed the reproduced sorted-lock failure; it needs a maintainer-triggered CI rerun to verify the current head.

@pelikhan
pelikhan merged commit 6db2a82 into main Sep 17, 2026
34 checks passed
@pelikhan
pelikhan deleted the copilot/bump-mcpg-version-0425 branch September 17, 2026 22:19
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.89.17

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants