Skip to content

Bump gh-aw-firewall and gh-aw-mcpg versions - #64917

Merged
pelikhan merged 4 commits into
mainfrom
copilot/update-gh-aw-mcpg-and-gh-aw-firewall-versions
Oct 2, 2026
Merged

pelikhan merged 4 commits into
mainfrom
copilot/update-gh-aw-mcpg-and-gh-aw-firewall-versions

Conversation

Copilot AI commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Update the pinned dependencies to gh-aw-firewall v0.28.31 and gh-aw-mcpg v0.4.28.

  • Version pins: Update the default versions and add verified digests for the five release images.
  • Generated artifacts: Regenerate workflow lockfiles and embedded container pin data.
  • Release metadata: Add a patch changeset.

Copilot AI linked an issue Oct 2, 2026 that may be closed by this pull request
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Copilot AI changed the title [WIP] Update gh-aw-mcpg and gh-aw-firewall to latest versions Bump gh-aw-firewall and gh-aw-mcpg versions Oct 2, 2026
Copilot AI requested a review from lpcox October 2, 2026 05:36
@pelikhan
pelikhan marked this pull request as ready for review October 2, 2026 06:24
Copilot AI balanced review requested due to automatic review settings October 2, 2026 06:24
@pelikhan

pelikhan commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

@copilot resolve the merge conflicts in this pull request

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unit expectations, model-routing image pins, and the embedded AWF schema remain stale.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity

Open (3)
What changed in this PR

Updates gh-aw defaults to gh-aw-firewall v0.28.31 and gh-aw-mcpg v0.4.28, including generated pins and workflows.

Changes:

  • Bumps both default dependency versions.
  • Adds verified container digests and regenerates affected lockfiles.
  • Adds a patch changeset.
File Description
pkg/​constants/​version_constants.go Updates default versions.
pkg/​actionpins/​data/​action_pins.json Adds container digests.
pkg/​workflow/​data/​action_pins.json Updates embedded pins.
.github/​aw/​actions-lock.json Updates compiler pin data.
.github/​workflows/​smoke-crush.lock.yml Regenerates dependency references.
.github/​workflows/​smoke-ci.lock.yml Regenerates dependency references.
.github/​workflows/​notion-issue-summary.lock.yml Regenerates dependency references.
.github/​workflows/​hippo-embed.lock.yml Regenerates dependency references.
.github/​workflows/​firewall.lock.yml Regenerates dependency references.
.github/​workflows/​example-permissions-warning.lock.yml Regenerates dependency references.
.github/​workflows/​codex-github-remote-mcp-test.lock.yml Regenerates dependency references.
.changeset/​patch-bump-awf-v0-28-31-mcpg-v0-4-28.md Records the patch release change.

@@ -68,7 +68,7 @@ const DefaultGitHubMCPServerVersion Version = "v1.12.2"
//
// The first recompile regenerates all lock files using the new version; the second recompile
// refreshes the container SHA pins that were resolved during the first pass.
const DefaultFirewallVersion Version = "v0.28.30"
const DefaultFirewallVersion Version = "v0.28.31"
@@ -68,7 +68,7 @@ const DefaultGitHubMCPServerVersion Version = "v1.12.2"
//
// The first recompile regenerates all lock files using the new version; the second recompile
// refreshes the container SHA pins that were resolved during the first pass.
const DefaultFirewallVersion Version = "v0.28.30"
const DefaultFirewallVersion Version = "v0.28.31"
@@ -68,7 +68,7 @@ const DefaultGitHubMCPServerVersion Version = "v1.12.2"
//
// The first recompile regenerates all lock files using the new version; the second recompile
// refreshes the container SHA pins that were resolved during the first pass.
const DefaultFirewallVersion Version = "v0.28.30"
const DefaultFirewallVersion Version = "v0.28.31"
…mcpg-and-gh-aw-firewall-versions

# Conflicts:
#	.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml
#	.github/workflows/daily-mcp-concurrency-analysis.lock.yml
#	.github/workflows/smoke-builtin-ledgers.lock.yml

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

@copilot resolve the merge conflicts in this pull request

Merged origin/main and regenerated the conflicted workflow lockfiles. Merge commit: 9f246342d5.

Copilot AI requested a review from pelikhan October 2, 2026 06:48
@pelikhan
pelikhan merged commit f99054c into main Oct 2, 2026
2 checks passed
@pelikhan
pelikhan deleted the copilot/update-gh-aw-mcpg-and-gh-aw-firewall-versions branch October 2, 2026 07:22
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.90.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bump gh-aw-mcpg and gh-aw-firewall versions

4 participants