Bump MCP Gateway to v0.4.25 - #61661
Conversation
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
There was a problem hiding this comment.
🔵 Needs a closer look
The update spans 299 regenerated workflow locks, warranting final human review.
Pull request overview
Bumps the MCP Gateway image from v0.4.23 to v0.4.25 with a refreshed immutable digest and regenerated workflow locks.
Changes:
- Updated version constants and pin data.
- Regenerated reviewed workflow lockfiles.
- Added a patch changeset.
File summaries
| File | Summary |
|---|---|
pkg/workflow/data/action_pins.json |
Updated workflow container pin. |
pkg/constants/version_constants.go |
Bumped default gateway version. |
pkg/constants/version_constants_test.go |
Updated version expectation. |
pkg/actionpins/data/action_pins.json |
Updated embedded container pin. |
.github/workflows/windows.lock.yml |
Regenerated with the new gateway pin. |
.github/workflows/smoke-copilot-small.lock.yml |
Regenerated with the new gateway pin. |
.github/workflows/schema-feature-coverage.lock.yml |
Regenerated with the new gateway pin. |
.github/workflows/github-remote-mcp-auth-test.lock.yml |
Regenerated with the new gateway pin. |
.github/workflows/firewall.lock.yml |
Regenerated with the new gateway pin. |
.github/workflows/draft-pr-cleanup.lock.yml |
Regenerated with the new gateway pin. |
.github/workflows/daily-team-status.lock.yml |
Regenerated with the new gateway pin. |
.github/workflows/daily-squid-image-scan.lock.yml |
Regenerated with the new gateway pin. |
.github/workflows/daily-spec-coverage-kiro.lock.yml |
Regenerated with the new gateway pin. |
.github/workflows/daily-schema-audit-cursor.lock.yml |
Regenerated with the new gateway pin. |
.github/workflows/daily-regression-audit-kiro.lock.yml |
Regenerated with the new gateway pin. |
.github/workflows/daily-pr-review-cursor.lock.yml |
Regenerated with the new gateway pin. |
.github/workflows/daily-github-docs-seo-optimizer.lock.yml |
Regenerated with the new gateway pin. |
.github/workflows/daily-community-attribution.lock.yml |
Regenerated with the new gateway pin. |
.github/workflows/copilot-pr-merged-report.lock.yml |
Regenerated with the new gateway pin. |
.github/workflows/codex-github-remote-mcp-test.lock.yml |
Regenerated with the new gateway pin. |
.github/workflows/breaking-change-checker.lock.yml |
Regenerated with the new gateway pin. |
.github/aw/actions-lock.json |
Updated immutable container digest. |
.changeset/upgrade-gh-aw-mcpg-v0-4-25.md |
Added patch changeset. |
Review details
- Files reviewed: 69/305 changed files
- Comments generated: 0
- Review effort level: Lite (auto)
Note
Copilot is running an experiment and ran this review at Lite.
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
|
Warning Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding. What happenedThe threat detection engine failed to produce results. Review the workflow run logs for details.
|
|
✅ Test Quality Sentinel completed test quality analysis. Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch PR file list
|
|
✅ Ponytail Reviewer completed successfully! Cannot run ponytail review: /tmp/gh-aw/agent/pr-diff.patch is empty (0 bytes), so there is no diff to review. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"See Network Configuration for more information.
|
|
🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
|
|
No ADR enforcement needed: PR does not have the 'implementation' label and has <=100 new lines of code in business logic directories.
|
|
@copilot This PR looks blocked on maintainer follow-up rather than active checks. Please review the current feedback, refresh the branch if needed, and run the Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
|
There was a problem hiding this comment.
Skills-Based Review 🧠
This is a mechanical dependency bump (MCP Gateway v0.4.23 → v0.4.25): version constant, container digest pin (synced across both action_pins.json copies), changeset, and 299 regenerated .lock.yml files. No application logic, control flow, or test-relevant behavior changed, so /diagnosing-bugs, /tdd, and /codebase-design don't surface actionable findings here.
📋 Verification performed
DefaultMCPGatewayVersioninpkg/constants/version_constants.goand its test expectation both updated tov0.4.25.- Digest
sha256:9be0a862...is identical across.github/aw/actions-lock.json,pkg/actionpins/data/action_pins.json, andpkg/workflow/data/action_pins.json. - No stale
v0.4.23references remain in any.lock.ymlfile (checked all 299). - Changeset present and correctly scoped as
patch.
No blocking issues found.
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
github.com
To allow these domains, add them to the network.allowed list in your workflow frontmatter:
network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 39 AIC · ⌖ 14.9 AIC · ⊞ 10.6K
Comment /matt to run again
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Addressed in |
|
@copilot The latest push addressed the previous sous-chef nudge, but this PR still appears blocked on maintainer follow-up. Please review any remaining feedback, refresh the branch if needed, and run the Failed checks to review:
Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "github.com"See Network Configuration for more information.
|
Ran the The listed Design Decision Gate run is successful on attempt 2. The PR Code Quality Reviewer failure is from the earlier head |
|
🎉 This pull request is included in a new release. Release: |
Upgrades the pinned MCP Gateway (
gh-aw-mcpg) Docker image fromv0.4.23tov0.4.25.Version constant
DefaultMCPGatewayVersion→v0.4.25inpkg/constants/version_constants.go, with the matching expectation inversion_constants_test.go.Container pin
.github/aw/actions-lock.jsoncontainer pin replaced with the immutable digest for the new tag, and synced topkg/actionpins/data/action_pins.jsonandpkg/workflow/data/action_pins.json:Regenerated workflows
.lock.ymlfiles recompiled so manifests,download_docker_images.sharguments, andMCP_GATEWAY_DOCKER_COMMANDreference the new pinned image.Changeset
.changeset/upgrade-gh-aw-mcpg-v0-4-25.md(patch).Minimum-version gates (
MCPGIntegrityReactionsMinVersion,MCPGEnclave*MinVersion,MCPGDynamicRepositoryDelegationMinVersion) are unchanged — no new capability gates in this release.Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
github.laiyagushi.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.