Skip to content

Add Daily Ecosystem Explorer agentic workflow - #64096

Merged
pelikhan merged 1 commit into
mainfrom
copilot/add-daily-agentic-workflows
Sep 29, 2026
Merged

pelikhan merged 1 commit into
mainfrom
copilot/add-daily-agentic-workflows

Conversation

Copilot AI commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Adds a daily workflow that works through the gh-aw extension and tools ecosystem a few projects at a time. It keeps its progress in repo-memory and writes a blog post for projects that score highly. Adapted from daily-agent-of-the-day-blog-writer.md.

Files: .github/workflows/daily-ecosystem-explorer.md and its compiled .lock.yml. The workflow has not been run yet.

Repo-memory state (memory/ecosystem-explorer branch)

  • backlog.json: projects queued for review, oldest first.
  • reviewed.json: one entry per reviewed project, with a 1–10 score, a one-line summary, cited highlights and a blogged flag.
  • discovery.json: search queries already used, so they rotate on a 14-day window.
  • runs.md: one line per run, trimmed to the last 200 lines.

Run loop

  • Discover (only when the backlog has fewer than 10 items):

    • repo topics gh-aw and agentic-workflows
    • code search for gh-aw frontmatter markers
    • gh-* CLI extensions
    • shared components and MCP servers
    • githubnext/agentics and githubnext/agentic-ops

    Forks, archived repos, already-reviewed projects and github/gh-aw itself are skipped.

  • Explore: reviews up to 3 projects per run, scored on novelty, usefulness, guardrails, docs and maintenance.

  • Blog: picks the top unblogged project scoring ≥ 8, even if it was reviewed on an earlier day. It writes docs/src/content/docs/blog/YYYY-MM-DD-ecosystem-spotlight.md explaining why the project stands out and opens a draft [blog] PR. Otherwise the run ends with noop and a short summary.

Guardrails

  • Read-only permissions, strict mode and the AWF sandbox. The generated PR can only touch docs/src/content/docs/blog/**.
  • Runs on a fuzzy daily schedule and is skipped while an Ecosystem Spotlight blog PR is still open.
  • The agent treats content from other repos as untrusted: it ignores instructions found there and never runs their code.
  • No web-fetch: strict mode rejects it for Copilot because it bypasses the network allowlist. Discovery uses the GitHub MCP repos and search toolsets instead.

Security review note

Compiling added four restricted secrets from the shared shared/otlp.md telemetry import, which the Agent of the Day workflow already uses:

  • GH_AW_OTEL_GRAFANA_AUTHORIZATION
  • GH_AW_OTEL_GRAFANA_ENDPOINT
  • GH_AW_OTEL_SENTRY_AUTHORIZATION
  • GH_AW_OTEL_SENTRY_ENDPOINT

They are only used to export telemetry. No new third-party actions were added. Reviewers should confirm these are acceptable for this workflow.



✨ PR Review Safe Output Test - Run 36502480499

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • clients2.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "clients2.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · claude · sonnet46 · 53.5 AIC · ⌖ 17 AIC · ⊞ 8K · ◷
Comment /smoke-claude to run again

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Comment on lines +34 to +41
bash: ["*"]
github:
mode: local
lockdown: false
min-integrity: approved
toolsets:
- repos
- search
@pelikhan
pelikhan marked this pull request as ready for review September 29, 2026 00:25
Copilot AI balanced review requested due to automatic review settings September 29, 2026 00:25
@pelikhan
pelikhan merged commit 09e40b7 into main Sep 29, 2026
1 check passed
@pelikhan
pelikhan deleted the copilot/add-daily-agentic-workflows branch September 29, 2026 00:25

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • clients2.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "clients2.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · claude · sonnet46 · 53.5 AIC · ⌖ 17 AIC · ⊞ 8K
Comment /smoke-claude to run again

private: true
emoji: "🧭"
name: Daily Ecosystem Explorer
description: Systematically explores the GitHub Agentic Workflows extension and tools ecosystem, tracks progress in repo-memory, and writes a blog post when an extension stands out

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Great description! Consider adding a note about the frequency of blog post generation to help reviewers understand expected output volume.

schedule: daily
workflow_dispatch:
skip-if-match: 'is:pr is:open label:blog in:title "Ecosystem Spotlight"'
max-daily-ai-credits: 10000

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚙️ The max-daily-ai-credits: 10000 limit looks reasonable for daily exploration. It might be worth documenting the rationale for this value in comments for future reference.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Copilot review overview

Review effort: Lite
Findings: 4 Medium severity

Open (4)
What changed in this PR

Adds a new “Daily Ecosystem Explorer” gh-aw workflow that continuously discovers and reviews gh-aw ecosystem projects, persists its progress in repo-memory, and drafts an “Ecosystem Spotlight” blog PR when a project scores highly.

Changes:

  • Introduces a new daily agentic workflow prompt/spec for discovery → review → blog → memory update.
  • Adds safe-outputs constraints to limit PR writes to docs/src/content/docs/blog/** and uses repo-memory on a dedicated branch.
  • Commits the compiled .lock.yml GitHub Actions workflow generated from the .md source.
File Description
.github/​workflows/​daily-ecosystem-explorer.md Defines the agent behavior, repo-memory schema, blogging rules, and safety constraints.
.github/​workflows/​daily-ecosystem-explorer.lock.yml Generated workflow implementation (jobs, containers, permissions, safe-outputs enforcement) for execution on GitHub Actions.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +1274 to +1278
permissions:
actions: read
contents: write
issues: write
pull-requests: write
description: "Exploration backlog, reviewed extensions/tools with scores, and blog history for the gh-aw ecosystem explorer"
file-glob: ["*.json", "*.md"]
max-file-size: 102400
safe-outputs:

### 5) Write the blog post

Create `docs/src/content/docs/blog/YYYY-MM-DD-ecosystem-spotlight.md` (UTC date; append `-2`, `-3` if it exists). Look at an existing post under `docs/src/content/docs/blog/` for frontmatter conventions.

### 7) Finish with exactly one safe output

- `create_pull_request` when a blog post was written. Title: `Ecosystem Spotlight – <name>`. Body: why it was chosen, score and highlights, evidence links, and the file path. The patch must only contain files under `docs/src/content/docs/blog/`. Do not run git write commands yourself.
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.90.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants