Repository navigation
chore(deps): update dependency github/gh-aw to v0.89.21 - #401
Open
bootc-bot[bot] wants to merge 1 commit into
Open
bootc-bot[bot] wants to merge 1 commit into
bootc-bot[bot] wants to merge 1 commit into
Conversation
Signed-off-by: bootc-bot[bot] <225049296+bootc-bot[bot]@users.noreply.github.com> Signed-off-by: bootc-bot[bot] <225049296+bootc-bot[bot]@users.noreply.github.com>
bootc-bot
Bot
force-pushed
the
bootc-renovate/github-actions
branch
from
October 11, 2026 01:07
8a1f1d7 to
03e2a43
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.88.7→v0.89.21Release Notes
github/gh-aw
v0.89.21Compare Source
🌟 Release Highlights
This release brings native web-search support for the Copilot engine, more flexible reusable-workflow failure reporting, and hardened safe-outputs checkout detection.
✨ What's New
tools: web-search:now compiles to Copilot's built-inweb_searchtool (--allow-tool web_search) instead of producing a compile warning, making web search usable even in repos without GitHub tooling (e.g. Azure DevOps-hosted). See Web Search reference. (#62957)failure-issue-repofor reusable workflows —safe-outputs.failure-issue-reponow accepts${{ inputs.* }}expressions, matching existing support forreport-failure-as-issueandreport-failed-jobs, so reusable (workflow_call) workflows can route failure issues per caller without patching the compiled lock file. (#62945)gh aw auditnow surfacestoken_steeringandtimeout_steeringevents (type, message, timestamp) asgateway_steering_eventsin both JSON and console output, making it easier to see when runs are approaching AI Credit or time limits. (#62943)🐛 Bug Fixes & Improvements
find_repo_checkoutgit-scan fallback now trusts scanned repositories cloned via asteps:entry or manualactions/checkout, fixing a regression where the containerized safe-outputs MCP server (different UID) couldn't read nested checkouts due to git'ssafe.directorytrust not propagating beyondGITHUB_WORKSPACE. (#62944)📚 Documentation
.lock.ymlfiles viagh aw list --jsonfor CI enforcement, plus remediation steps for contributors. (#62947)RUNNER_TEMPinstead of a hardcoded/tmp, for portability across runner environments. (#62940)🔧 Internal
What's Changed
${{ inputs.* }}expressions insafe-outputs.failure-issue-repofor reusable workflows by @pelikhan with @Copilot in #62945Full Changelog: github/gh-aw@v0.89.20...v0.89.21
v0.89.20Compare Source
🌟 Release Highlights
This release focuses on reliability fixes for cross-repo pull request handling, threat-detection infrastructure, and Linear/Jira safe-output integrations, alongside continued documentation and automation upkeep.
🐛 Bug Fixes & Improvements
create_pull_requestnow passes the validated head repository, so PRs from forks that share an organization with the base repo no longer fail (#62720).RUNNER_TEMPdirectory and installed rootlessly, resolving failures where the runner and Docker daemon don't share a filesystem (#62755).create_issuenow accepts a team UUID, key, or friendly name instead of requiring a UUID (#62754), and workflow activation now validatesLINEAR_TEAM_IDup front to prevent silent handler load failures (#62743).gh aw auditnow surfaces failed detection jobs and reports detected threats with stable finding codes for downstream automation (#62753).gh-awbinary downloads are now staged before replacing existing binaries, preventing partial upgrades (#62761).workflows-scope timeouts when pushing branches forcreate_pull_requestandpush_to_pull_request_branch(#62486, #62668).nl,sed) in the PR Code Quality Reviewer to prevent premature harness stops (#62770).✨ What's New
jira-create-issue,jira-update-issue,jira-add-comment, andjira-add-labelare now stable, production-ready safe outputs (#62749).📚 Documentation
What's Changed
Full Changelog: github/gh-aw@v0.89.19...v0.89.20
v0.89.17Compare Source
🌟 Release Highlights
This release focuses on hardening reliability across the AIC accounting pipeline, AWF/firewall integration, and safe-outputs handling, alongside a refreshed model catalog and several documentation clean-ups.
✨ What's New
gemini-3.8-flashandclaude-fable-5.1aliases and corrected pricing forgpt-6-astra/gpt-5.6-sol(#61234).gh-aw-firewall(AWF) updated to v0.28.20 (#61527) and v0.28.17 (#60945), improving compatibility and stability.🐛 Bug Fixes & Improvements
curlversions in the AWF installer (#61600).experiments.<name>references inengine.modelinto valid job-scoped expressions, preventing invalid compiled workflows (#61599).withRetryagainst transient fetch failures (#61439).upload_artifactsilently succeeding when relative paths were never staged (#61431).add_labelslists are now treated as a no-op instead of failing the job (#61429).model(#61424).PLAYWRIGHT_BROWSERS_PATHnow uses${{ runner.temp }}so install and launch agree on the browser path (#61423).not_startedexecution evidence is recorded when AWF fails before the engine harness starts (#61202).ci-coach(#61201).pkg/clitest-unit crash from concurrent Cobra completion generation (#61146).📚 Documentation
report-as-issuefield (#61563).What's Changed
Full Changelog: github/gh-aw@v0.89.16...v0.89.17
v0.89.15Compare Source
What's Changed
Full Changelog: github/gh-aw@v0.89.14...v0.89.15
v0.89.13Compare Source
🌟 Release Highlights
A small maintenance release focused on logs tooling, release-notes governance, and a documentation fix.
✨ What's New
gh aw logs --cached-logsnow accepts trailing-wildcard prefixes (e.g.logs-*), merging all matching*.jsonlshards, pruning out-of-range files, and writing fresh results to a new collision-resistant shard. Handy for teams sharing rolling log caches. (#60702)update-releasesafe output instead of direct GitHub mutations, keeping agent jobs read-only and closing off a class of unintended writes. (#60701)📚 Documentation
aw-infoandpromptas current artifact names even though no compiled workflow produces them; the correctinfoartifact is now documented, and the legacy names are marked back-compat. (#60706)🔧 Internal
No community-labeled issues were closed in this release window.
What's Changed
Full Changelog: github/gh-aw@v0.89.12...v0.89.13
v0.89.12Compare Source
🌟 Release Highlights
A small security-hardening and CI reliability release.
🐛 Bug Fixes & Improvements
.github/workflows/agentic_commands.yml) now checks out the repository withpersist-credentials: false, soGITHUB_TOKENis no longer persisted in the local git config for the lifetime of the routing job (#60685).What's Changed
Full Changelog: github/gh-aw@v0.89.11...v0.89.12
v0.89.11Compare Source
🌟 Release Highlights
This release focuses on reliability hardening for agentic workflow execution — fixing model-compatibility bugs, improving error detection, and closing safety gaps in the linter autofix pipeline.
🐛 Bug Fixes & Improvements
-fixruns; added regression coverage to keep diagnostics safe.400 Bad Requestresponses instead of misreporting them as partial execution, avoiding futile retries..jsonlfiles so rows added by parallel workflow runs are no longer discarded.🔧 Dependencies
gh-aw-firewalltov0.28.16andgh-aw-mcpgtov0.4.21(#60568), refreshing container digest pins across all workflow lock files.🤖 New Linter
bufio-scanner-err-unchecked(#60660), which flagsbufio.Scannerloops that don't checkErr()after completion — catching silently dropped I/O errors. Found and helped fix 9 real instances in this codebase.No community-labeled issues were resolved in this release window.
What's Changed
Full Changelog: github/gh-aw@v0.89.10...v0.89.11
v0.89.10Compare Source
🌟 Release Highlights
This release focuses on reliability improvements to the AI Credits (AIC) accounting guardrail, plus a package-manifest enhancement for shared JavaScript workflow modules.
✨ What's New
aw.ymlpackages — Package manifests can now ship.mjsand.cjshelper files alongside shared workflows under.github/workflows/shared/, with path traversal and extension restrictions preserved. See the imports reference.gh aw logs— Rate-limit state is now shared across concurrent log-download targets, so queued work is cancelled once the shared ceiling is reached instead of blocking until reset. Single-target downloads retain the existing wait-for-reset behavior.🐛 Bug Fixes & Improvements
not_started→started) to distinguish "never ran" from "lost accounting data."📚 Documentation
What's Changed
Full Changelog: github/gh-aw@v0.89.9...v0.89.10
v0.89.9Compare Source
🌟 Release Highlights
This release focuses on reliability improvements for AI credit accounting, logs tooling, and workflow updates, plus a couple of targeted bug fixes.
✨ What's New
gh aw update— the update command now targets packages individually, making it easier to keep multi-package workflow setups current (#60452).🐛 Bug Fixes & Improvements
openai/provider prefix from model identifiers, preventing misconfigured model lookups (#60423, closes #60416).What's Changed
openai/provider prefix from Codex model identifiers by @pelikhan with @Copilot in #60423gh aw updateby @pelikhan with @Copilot in #60452Full Changelog: github/gh-aw@v0.89.8...v0.89.9
v0.89.8Compare Source
🌟 Release Highlights
This release strengthens billing and guardrail accuracy for AI Credits, hardens safe-output permission enforcement, and adds new configuration flexibility for OTLP telemetry and agent assignment.
✨ What's New
secrets.GH_AW_DEFAULT_OTLP_ENDPOINTin addition to visible variables, with automatic fallback and existing precedence preserved.assign-to-agent— Forward model-specificreasoning_effort(e.g.high) through agent assignment, with automatic validation and graceful fallback for unsupported agents/models.continue-on-erroron generated agent jobs — The compiler now correctly preserves an explicitcontinue-on-error: true/falseon the generatedagentjob instead of silently dropping it.gh aw logs --cached-jsonlnow prunes cached run records outside the requested--start-date/--end-daterange instead of only appending, keeping cached history accurate.pre_activationnow automatically receivespull-requests: readwhen a workflow defines a centralized slash command, fixing silent execution skips on pull requests.🐛 Bug Fixes & Improvements
add_labelsto enforce configured targets, preventing labels from being applied outside the triggering issue or PR unless explicitly allowed viatarget: "*".EACCES) in Claude stream-JSON output from incorrectly triggering failure classifiers and suppressing retries.📚 Documentation
What's Changed
Full Changelog: github/gh-aw@v0.89.7...v0.89.8
v0.89.7Compare Source
🌟 Release Highlights
A focused maintenance release improving the reliability of
gh aw logsmulti-target downloads and tightening the safe-outputs compiler for enclave configurations.✨ What's New
gh aw logs --countdownloads — When multiple workflow targets share a--countbudget, sibling targets are now cancelled promptly as soon as the shared limit is reached, instead of finishing an in-flight over-fetched chunk first (#60323, #60343). This reduces wasted API calls and speeds up multi-target log retrieval.🐛 Bug Fixes & Improvements
GH_AW_SINK_VISIBILITYreferenced adetermine-automatic-lockdownstep that was never generated whentools.github: falsewas combined with a static GitHub enclave and safe-outputs, which could break workflow compilation for that configuration (#60338).lint-go-golangciCI job (#60316).🔧 Internal
slice-make-zero-length, to catchmake([]T, 0)calls without a capacity argument (#60310).No breaking changes in this release.
What's Changed
Full Changelog: github/gh-aw@v0.89.6...v0.89.7
v0.89.6Compare Source
🌟 Release Highlights
A small, focused patch release: a
gh aw logsreliability fix for multi-target downloads and a compiler tweak that relaxes an experimental-runtime warning.🐛 Bug Fixes & Improvements
gh aw logsmulti-target downloads now respect--count/--timeout— Previously, runninggh aw logsagainst multiple targets could over-fetch (~3× the requested count per target) and silently truncate results when a shared timeout expired mid-run, leaving continuations withtimeout: 0. Each target now caps its work against the remaining shared budget, and per-target timeouts are correctly inherited so continuations replay with the original timeout. (#60308)cloud-hypervisorsandbox runtime — The compiler no longer emits this warning whensandbox.agent.runtime: cloud-hypervisoris set; the runtime remains in experimental preview and still requires--cloud-hypervisor-preview. (#60304)No community-labeled issues were closed in this release window.
What's Changed
Full Changelog: github/gh-aw@v0.89.5...v0.89.6
v0.89.5Compare Source
🌟 Release Highlights
This release focuses on hardening safe-output reliability, tightening security around confused-deputy protections, and improving multi-target log collection under load.
✨ What's New
safe-outputs.body-footerlets you append shared, additive content to every safe output that produces a body, composing cleanly across imported workflows and handler-specific config. Learn moreaw_info.jsonas an archived artifact, fixing compatibility with GitHub Enterprise where unarchived artifacts aren't supported.🐛 Bug Fixes & Improvements
synchronizeevents; the bot allowlist is now checked first.🔧 Internal
@primer/octicons,@types/node,@astrojs/sitemap,starlight-links-validator,@astrojs/starlight), package specification refreshes, and dead-code removal.What's Changed
Configuration
📅 Schedule: (in timezone UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.