diff --git a/.github/workflows/smoke-cursor.lock.yml b/.github/workflows/smoke-cursor.lock.yml index 123d9ab7106..99c2ce23a8c 100644 --- a/.github/workflows/smoke-cursor.lock.yml +++ b/.github/workflows/smoke-cursor.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"33e6c36679cd4125f7a8e3f39809096478ab575a52a8db6ae3d13e020c589790","body_hash":"012d90a7aa18bec3aa38ed090baa3606bd70857473f155723a6f5e3192d7af0f","strict":true,"agent_id":"cursor","agent_model":"cursor/auto"} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"4f80d0aa510b185eed62b1a00845b42a0a6b80a6fbc7408ac01bde4fcc072d48","body_hash":"da3331d38b2ef72929ef4132bcf7325849d5d28d15f2b7f13a653b7a9349670e","strict":true,"agent_id":"cursor","agent_model":"cursor/auto"} # gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","CURSOR_API_KEY","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.28.10","digest":"sha256:c01e6d16d11ea4f2a46cc023a9f402224a3b3861b026818eec0dc586d7e6918e","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.28.10@sha256:c01e6d16d11ea4f2a46cc023a9f402224a3b3861b026818eec0dc586d7e6918e"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.10","digest":"sha256:c3a18aebb8251339117ea998296315de17bada366f8d03919b3348ea71112e64","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.10@sha256:c3a18aebb8251339117ea998296315de17bada366f8d03919b3348ea71112e64"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.28.10","digest":"sha256:c06076f7aca95df713e0748c44d80c0a3c2538fad67bfdd04296d45158e083e6","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.28.10@sha256:c06076f7aca95df713e0748c44d80c0a3c2538fad67bfdd04296d45158e083e6"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.14","digest":"sha256:b2f0c2b2f17b5fbe809e5bb99dc185b6ddd70df25295dc63a6d526350334eff5","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.14@sha256:b2f0c2b2f17b5fbe809e5bb99dc185b6ddd70df25295dc63a6d526350334eff5"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:bac2192f6374d6262116399b34fc5e143d576f82719e90a18261cae7480f4d4e","pinned_image":"ghcr.io/github/gh-aw-node@sha256:bac2192f6374d6262116399b34fc5e143d576f82719e90a18261cae7480f4d4e"},{"image":"ghcr.io/github/github-mcp-server:v1.11.0","digest":"sha256:fbec75de11c255213fa08d80fb166abe73d851fff631c51c0079872967720699","pinned_image":"ghcr.io/github/github-mcp-server:v1.11.0@sha256:fbec75de11c255213fa08d80fb166abe73d851fff631c51c0079872967720699"}],"has_pull_request":true,"mcp_servers":[{"name":"github","tools":["get_commit","get_file_contents","get_latest_release","get_me","get_pull_request","get_pull_request_comments","get_pull_request_diff","get_pull_request_files","get_pull_request_review_comments","get_pull_request_reviews","get_pull_request_status","get_release_by_tag","get_tag","issue_read","list_branches","list_commits","list_issue_types","list_issues","list_pull_requests","list_releases","list_starred_repositories","list_tags","pull_request_read","search_code","search_issues","search_pull_requests","search_repositories"]},{"name":"safeoutputs","tools":["add_comment","add_labels","create_issue","missing_data","missing_tool","noop"]}]} # This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # @@ -33,7 +33,6 @@ # - shared/reporting.md # - shared/reporting-otlp.md # - shared/smoke-test-brevity.md -# - shared/token-telemetry-check.md # # Secrets used: # - COPILOT_GITHUB_TOKEN @@ -337,7 +336,7 @@ jobs: GH_AW_ACTIONS_DIR: ${{ runner.temp }}/gh-aw/actions GH_AW_PROMPT: ${{ runner.temp }}/gh-aw/aw-prompts/prompt.txt GH_AW_SAFE_OUTPUTS: ${{ runner.temp }}/gh-aw/safeoutputs/outputs.jsonl - GH_AW_PROMPT_CONFIG: "{\"items\":[{\"content_env\":\"GH_AW_PROMPT_CONTENT_0000\"},{\"file\":\"xpia.md\"},{\"file\":\"temp_folder_prompt.md\"},{\"file\":\"markdown.md\"},{\"file\":\"safe_outputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0001\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0002\"},{\"file\":\"mcp_cli_tools_with_safeoutputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0003\"},{\"file\":\"github_mcp_tools_with_safeoutputs_prompt.md\"},{\"file\":\"pr_context_prompt.md\",\"condition_env\":\"GH_AW_INCLUDE_PR_CONTEXT\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0004\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0005\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0006\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0007\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0008\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0009\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0010\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0011\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0012\"}]}" + GH_AW_PROMPT_CONFIG: "{\"items\":[{\"content_env\":\"GH_AW_PROMPT_CONTENT_0000\"},{\"file\":\"xpia.md\"},{\"file\":\"temp_folder_prompt.md\"},{\"file\":\"markdown.md\"},{\"file\":\"safe_outputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0001\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0002\"},{\"file\":\"mcp_cli_tools_with_safeoutputs_prompt.md\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0003\"},{\"file\":\"github_mcp_tools_with_safeoutputs_prompt.md\"},{\"file\":\"pr_context_prompt.md\",\"condition_env\":\"GH_AW_INCLUDE_PR_CONTEXT\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0004\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0005\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0006\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0007\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0008\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0009\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0010\"},{\"content_env\":\"GH_AW_PROMPT_CONTENT_0011\"}]}" GH_AW_EXPR_1A3A194A: ${{ github.event.discussion.number || (fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_type == 'discussion' && fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_number) }} GH_AW_EXPR_463A214A: ${{ github.event.pull_request.number || (fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_type == 'pull_request' && fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_number) }} GH_AW_EXPR_802A9F6A: ${{ github.event.issue.number || (fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_type == 'issue' && fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_number) }} @@ -357,10 +356,9 @@ jobs: GH_AW_PROMPT_CONTENT_0006: "{{#runtime-import .github/workflows/shared/gh.md}}\n" GH_AW_PROMPT_CONTENT_0007: "{{#runtime-import .github/workflows/shared/reporting-otlp.md}}\n" GH_AW_PROMPT_CONTENT_0008: "{{#runtime-import .github/workflows/shared/otlp.md}}\n" - GH_AW_PROMPT_CONTENT_0009: "{{#runtime-import .github/workflows/shared/token-telemetry-check.md}}\n" - GH_AW_PROMPT_CONTENT_0010: "{{#runtime-import .github/workflows/shared/smoke-test-brevity.md}}\n" - GH_AW_PROMPT_CONTENT_0011: "{{#runtime-import .github/workflows/shared/reporting.md}}\n" - GH_AW_PROMPT_CONTENT_0012: "{{#runtime-import .github/workflows/smoke-cursor.md}}\n" + GH_AW_PROMPT_CONTENT_0009: "{{#runtime-import .github/workflows/shared/smoke-test-brevity.md}}\n" + GH_AW_PROMPT_CONTENT_0010: "{{#runtime-import .github/workflows/shared/reporting.md}}\n" + GH_AW_PROMPT_CONTENT_0011: "{{#runtime-import .github/workflows/smoke-cursor.md}}\n" with: script: | const { setupGlobals } = require(process.env.GH_AW_ACTIONS_DIR + '/setup_globals.cjs'); @@ -1375,77 +1373,10 @@ jobs: /tmp/gh-aw/sandbox/firewall/awf-reflect.json if-no-files-found: ignore - check_token_telemetry: - needs: agent - if: needs.agent.result == 'success' - runs-on: ubuntu-latest - permissions: - contents: read - steps: - - name: Configure GH_HOST for enterprise compatibility - id: ghes-host-config - shell: bash - run: | # zizmor: ignore[github-env] - GITHUB_SERVER_URL is set by GitHub Actions, not user input. - # Derive GH_HOST from GITHUB_SERVER_URL so the gh CLI targets the correct - # GitHub instance (GHES/GHEC). On github.com this is a harmless no-op. - GH_HOST="${GITHUB_SERVER_URL#https://}" - GH_HOST="${GH_HOST#http://}" - echo "GH_HOST=${GH_HOST}" >> "$GITHUB_ENV" - - name: Download agent artifact - id: download-agent - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 - with: - name: agent - path: /tmp/gh-aw/ - continue-on-error: true - - name: Assert token_usage.jsonl is non-empty - if: steps.download-agent.outcome == 'success' - run: | - # The AWF firewall proxy writes token_usage.jsonl for every LLM API call. - # If all token_usage.jsonl files are missing or empty, the emitter is broken. - TOKEN_FILES=( - "/tmp/gh-aw/sandbox/firewall-audit-logs/api-proxy-logs/token-usage.jsonl" - "/tmp/gh-aw/sandbox/firewall/audit/api-proxy-logs/token-usage.jsonl" - "/tmp/gh-aw/sandbox/firewall/logs/api-proxy-logs/token-usage.jsonl" - ) - - FOUND_NONEMPTY=false - for f in "${TOKEN_FILES[@]}"; do - if [ -s "$f" ]; then - COUNT=$(grep -c . "$f" 2>/dev/null || echo "0") - echo "OK: $f — ${COUNT} record(s)" - FOUND_NONEMPTY=true - else - [ -f "$f" ] && echo "EMPTY: $f" || echo "MISSING: $f" - fi - done - - if [ "${FOUND_NONEMPTY}" != "true" ]; then - echo "::error::All token_usage.jsonl files are empty or missing after a successful agent run." - echo "::error::The AWF firewall proxy token telemetry emitter may be broken." - exit 1 - fi - - name: Assert agent_usage.json has non-zero token counts - if: steps.download-agent.outcome == 'success' - run: | - USAGE_FILE="/tmp/gh-aw/agent_usage.json" - if [ ! -f "${USAGE_FILE}" ]; then - echo "::error::agent_usage.json not found in agent artifact — token summary was not written." - exit 1 - fi - INPUT_TOKENS=$(python3 -c "import json; d=json.load(open('${USAGE_FILE}')); print(d.get('input_tokens', 0))") - if [ "${INPUT_TOKENS}" -le 0 ]; then - echo "::error::agent_usage.json has zero input_tokens — token telemetry may be broken." - cat "${USAGE_FILE}" - exit 1 - fi - echo "OK: agent_usage.json reports ${INPUT_TOKENS} input tokens" - conclusion: needs: - activation - agent - - check_token_telemetry - detection - safe_outputs if: > diff --git a/.github/workflows/smoke-cursor.md b/.github/workflows/smoke-cursor.md index a26d5449005..cc6f2e414e4 100644 --- a/.github/workflows/smoke-cursor.md +++ b/.github/workflows/smoke-cursor.md @@ -28,7 +28,6 @@ imports: - shared/gh.md - shared/reporting-otlp.md - shared/otlp.md - - shared/token-telemetry-check.md - shared/smoke-test-brevity.md network: allowed: []