From 0c3b5ab54ad2ee16f53ad0ecbde173308e305497 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 1 Sep 2026 10:28:10 +0000 Subject: [PATCH 1/9] Bump sharp from 0.35.3 to 0.35.4 in /docs Bumps [sharp](https://github.com/lovell/sharp) from 0.35.3 to 0.35.4. - [Release notes](https://github.com/lovell/sharp/releases) - [Commits](https://github.com/lovell/sharp/compare/v0.35.3...v0.35.4) --- updated-dependencies: - dependency-name: sharp dependency-version: 0.35.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- docs/package-lock.json | 298 ++++++++++++++++++++++++----------------- docs/package.json | 2 +- 2 files changed, 179 insertions(+), 121 deletions(-) diff --git a/docs/package-lock.json b/docs/package-lock.json index d0f9292ef0a..75b4e1ea51b 100644 --- a/docs/package-lock.json +++ b/docs/package-lock.json @@ -17,7 +17,7 @@ "astro-mermaid": "^2.1.0", "mermaid": "^11.17.0", "pdfjs-dist": "^6.2.108", - "sharp": "^0.35.3", + "sharp": "^0.35.4", "starlight-blog": "^0.29.0", "starlight-changelogs": "^0.6.0", "starlight-links-validator": "^0.25.3", @@ -1327,9 +1327,9 @@ } }, "node_modules/@img/sharp-darwin-arm64": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/@img/sharp-darwin-arm64/-/sharp-darwin-arm64-0.35.3.tgz", - "integrity": "sha512-RMnFX7YQsMoh7lWfcM4NEHHymBX/rLuKNPVM84XE9ONPcaSCDgE7CHIHpSgPcO2xcRthgBy1HfNO319mwhIAkg==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/@img/sharp-darwin-arm64/-/sharp-darwin-arm64-0.35.4.tgz", + "integrity": "sha512-Uhfl4V4lhP2nbUVF9+hyH1+luj86f1gUFeo8ALYxFoULoU+G87D43BfeMP8XHsk9boxAnCY/bf2EHwhA7MuGsA==", "cpu": [ "arm64" ], @@ -1345,13 +1345,13 @@ "url": "https://opencollective.com/libvips" }, "optionalDependencies": { - "@img/sharp-libvips-darwin-arm64": "1.3.2" + "@img/sharp-libvips-darwin-arm64": "1.3.3" } }, "node_modules/@img/sharp-darwin-x64": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/@img/sharp-darwin-x64/-/sharp-darwin-x64-0.35.3.tgz", - "integrity": "sha512-Xo+5uFBtLN0BKqieTxiFzFPQAUlBbbH5iBKyRX/z1JrbnYsHTfKJnUfL8+p2TPXr1pXqao4eeL4Rl144uDpK9w==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/@img/sharp-darwin-x64/-/sharp-darwin-x64-0.35.4.tgz", + "integrity": "sha512-hWniXY3bG5qKpkKrAwPe4y+VTPmf086YQAnkxWh7uA1YrlRouWGa0M0Mxj3ZjnXFkv7/TD1bTy9lGUK26vRvWw==", "cpu": [ "x64" ], @@ -1367,20 +1367,20 @@ "url": "https://opencollective.com/libvips" }, "optionalDependencies": { - "@img/sharp-libvips-darwin-x64": "1.3.2" + "@img/sharp-libvips-darwin-x64": "1.3.3" } }, "node_modules/@img/sharp-freebsd-wasm32": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/@img/sharp-freebsd-wasm32/-/sharp-freebsd-wasm32-0.35.3.tgz", - "integrity": "sha512-lUxcqWIj2wMQ9BrwNjngcr1gWUr5xgaGThBRqPPalIC2n67Cqj1uPh8NnA/ZhAg8hUbKl+kVHKwgUIwe6ZYPrg==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/@img/sharp-freebsd-wasm32/-/sharp-freebsd-wasm32-0.35.4.tgz", + "integrity": "sha512-lIsKw/BU+kjB4eZjxrYrZmwOJYi3Ajrv66iAlBmUPyKc3HpnloevB1g3wxGD9P/5BbQ1brBGl65VRRrCvQDEqA==", "license": "Apache-2.0", "optional": true, "os": [ "freebsd" ], "dependencies": { - "@img/sharp-wasm32": "0.35.3" + "@img/sharp-wasm32": "0.35.4" }, "engines": { "node": ">=20.9.0" @@ -1390,9 +1390,9 @@ } }, "node_modules/@img/sharp-libvips-darwin-arm64": { - "version": "1.3.2", - "resolved": "https://registry.npmjs.org/@img/sharp-libvips-darwin-arm64/-/sharp-libvips-darwin-arm64-1.3.2.tgz", - "integrity": "sha512-9J6ypZFpQBj4YnePGoq/S38w6nz+vqg5WZLrLGY4YuSemdMq47GMLBPO42MzwdGwpg/agZ7xzZcFHa48xlywfg==", + "version": "1.3.3", + "resolved": "https://registry.npmjs.org/@img/sharp-libvips-darwin-arm64/-/sharp-libvips-darwin-arm64-1.3.3.tgz", + "integrity": "sha512-suTBPTDGrI9WodccaDdwZItTSaBYASlBk1NSfElSHrUfzu3szG6lvIF58+WiFvnfzuK8ZBFS5zE00PxqxnRiPg==", "cpu": [ "arm64" ], @@ -1406,9 +1406,9 @@ } }, "node_modules/@img/sharp-libvips-darwin-x64": { - "version": "1.3.2", - "resolved": "https://registry.npmjs.org/@img/sharp-libvips-darwin-x64/-/sharp-libvips-darwin-x64-1.3.2.tgz", - "integrity": "sha512-m2pW1n6cns9VaubNwsZ+c3CRYjxNQWgJ5gPlnL1nbBcpkBvFm6SCFN5o0psFHI8w9n11NKhFkeEDns98tiqbEw==", + "version": "1.3.3", + "resolved": "https://registry.npmjs.org/@img/sharp-libvips-darwin-x64/-/sharp-libvips-darwin-x64-1.3.3.tgz", + "integrity": "sha512-FVJZ5mITMobmXIz/hPDTw0EintTW5H3WfrxwLqEqjiIihlu+hVRyGrFQ60xl0Lxn7Bt3zdpevPaQi0HEzqz9fw==", "cpu": [ "x64" ], @@ -1422,12 +1422,15 @@ } }, "node_modules/@img/sharp-libvips-linux-arm": { - "version": "1.3.2", - "resolved": "https://registry.npmjs.org/@img/sharp-libvips-linux-arm/-/sharp-libvips-linux-arm-1.3.2.tgz", - "integrity": "sha512-1eMLzy92I4J6rmi4mAT8yC3HxOtniyGELlzGbNMLLeqe052ahFQ0h6LFq+lh5DsDIdYViIDst08abvSbcEdLXQ==", + "version": "1.3.3", + "resolved": "https://registry.npmjs.org/@img/sharp-libvips-linux-arm/-/sharp-libvips-linux-arm-1.3.3.tgz", + "integrity": "sha512-3rbU4vqXXc3hY/OiXdl52xZvT0F1yEngWfvqudtPJg/KkyiaQw2DRsFrNzpmLvfavbwOq3qXn36GP8obHRULQA==", "cpu": [ "arm" ], + "libc": [ + "glibc" + ], "license": "LGPL-3.0-or-later", "optional": true, "os": [ @@ -1438,12 +1441,15 @@ } }, "node_modules/@img/sharp-libvips-linux-arm64": { - "version": "1.3.2", - "resolved": "https://registry.npmjs.org/@img/sharp-libvips-linux-arm64/-/sharp-libvips-linux-arm64-1.3.2.tgz", - "integrity": "sha512-dqVSFynCox4C/J8kT16V7SIFAns0IjgLwkvYT7p8LQVmJ5OS5b6tI9IGflxTeuBS//zXeFIUbwt5dwxyZ17cnA==", + "version": "1.3.3", + "resolved": "https://registry.npmjs.org/@img/sharp-libvips-linux-arm64/-/sharp-libvips-linux-arm64-1.3.3.tgz", + "integrity": "sha512-0DaL0A6Xu6sQSQFwe4iVCrKWU2cCTItnRsYsCdxAMm9NF6twAA9BKnoqy4hqz4+azQ0JHuA26qiUKsf1XJ/v5A==", "cpu": [ "arm64" ], + "libc": [ + "glibc" + ], "license": "LGPL-3.0-or-later", "optional": true, "os": [ @@ -1454,12 +1460,15 @@ } }, "node_modules/@img/sharp-libvips-linux-ppc64": { - "version": "1.3.2", - "resolved": "https://registry.npmjs.org/@img/sharp-libvips-linux-ppc64/-/sharp-libvips-linux-ppc64-1.3.2.tgz", - "integrity": "sha512-3z0NHDxD6n5I9gc05U1eW1AyRm+Gznzq3naMrthPNqE6oYykcogW0l/jfpJdjYnuNl8R7yI9pNbE1XiUeyq0Aw==", + "version": "1.3.3", + "resolved": "https://registry.npmjs.org/@img/sharp-libvips-linux-ppc64/-/sharp-libvips-linux-ppc64-1.3.3.tgz", + "integrity": "sha512-cdn1OvUBwsXhbC0zSzJnNzf5MZ/mTrobawDvNXBTxe8VtqKAm0sRuEY2Evzovb/w9JMk4TvRxqt1mekSuJz64w==", "cpu": [ "ppc64" ], + "libc": [ + "glibc" + ], "license": "LGPL-3.0-or-later", "optional": true, "os": [ @@ -1470,12 +1479,15 @@ } }, "node_modules/@img/sharp-libvips-linux-riscv64": { - "version": "1.3.2", - "resolved": "https://registry.npmjs.org/@img/sharp-libvips-linux-riscv64/-/sharp-libvips-linux-riscv64-1.3.2.tgz", - "integrity": "sha512-bsb4rI+NldGOsXuej2r8OdSS8+zXDVaCWxyWrcv6kneTOlgAHtZABRzBBCwdsPiD90J4myNJuHpg6kA20ImW/w==", + "version": "1.3.3", + "resolved": "https://registry.npmjs.org/@img/sharp-libvips-linux-riscv64/-/sharp-libvips-linux-riscv64-1.3.3.tgz", + "integrity": "sha512-HjPVx7yKz+0lqdhDlTw1tt90wamBoxhiXpvl1XZpJLiHH4RCJ5yDTqH+VlYPv2fwFs89JFw4c1IexYOcQUi4IQ==", "cpu": [ "riscv64" ], + "libc": [ + "glibc" + ], "license": "LGPL-3.0-or-later", "optional": true, "os": [ @@ -1486,12 +1498,15 @@ } }, "node_modules/@img/sharp-libvips-linux-s390x": { - "version": "1.3.2", - "resolved": "https://registry.npmjs.org/@img/sharp-libvips-linux-s390x/-/sharp-libvips-linux-s390x-1.3.2.tgz", - "integrity": "sha512-/ABshyj8gCpyIrNXnHn4LorDJ0HHm1VhXPBlxZ8zAtfVPAaSafXPGn+sUSIRiwaSBy0mmFjSjiXI5mkcwdChKQ==", + "version": "1.3.3", + "resolved": "https://registry.npmjs.org/@img/sharp-libvips-linux-s390x/-/sharp-libvips-linux-s390x-1.3.3.tgz", + "integrity": "sha512-neWLh+3yCNThxnfy3c4BbVBeGgt9aftno+XbT56iK28RgeDs3UOFWviLWlUu0bArYVYJaFDK+RRohbicUNCm8Q==", "cpu": [ "s390x" ], + "libc": [ + "glibc" + ], "license": "LGPL-3.0-or-later", "optional": true, "os": [ @@ -1502,12 +1517,15 @@ } }, "node_modules/@img/sharp-libvips-linux-x64": { - "version": "1.3.2", - "resolved": "https://registry.npmjs.org/@img/sharp-libvips-linux-x64/-/sharp-libvips-linux-x64-1.3.2.tgz", - "integrity": "sha512-ITPEtgffGJ0S6G9dRyw/366tJQqFRcHWPHhC+Stpg3Z8AEMrDrTr2lhdz4f/Y/HMbRh//7Z5mBzEpVdi62Oc3w==", + "version": "1.3.3", + "resolved": "https://registry.npmjs.org/@img/sharp-libvips-linux-x64/-/sharp-libvips-linux-x64-1.3.3.tgz", + "integrity": "sha512-4vKmvAst9nrowcqquKFAyZJUDolUaIp8uRiN0mWFguJ1IplC9/pitXtlnnlU4aa/eJw3J7i67V+pwUL+wZGdsA==", "cpu": [ "x64" ], + "libc": [ + "glibc" + ], "license": "LGPL-3.0-or-later", "optional": true, "os": [ @@ -1518,12 +1536,15 @@ } }, "node_modules/@img/sharp-libvips-linuxmusl-arm64": { - "version": "1.3.2", - "resolved": "https://registry.npmjs.org/@img/sharp-libvips-linuxmusl-arm64/-/sharp-libvips-linuxmusl-arm64-1.3.2.tgz", - "integrity": "sha512-zE9EdiUzUmg5mDT5a1rk5fYJ6GWPloTwWBYDS14naqHsL+EaMpDj1AWnpLgh3u0YCORv2Tt50wrcrpYqkP97Kw==", + "version": "1.3.3", + "resolved": "https://registry.npmjs.org/@img/sharp-libvips-linuxmusl-arm64/-/sharp-libvips-linuxmusl-arm64-1.3.3.tgz", + "integrity": "sha512-Y9kQaLMuNoB0bPYOOdcZMaseNrFpPodIWWMrx+CZyydf2xn68j9WYc6sWWRrDwNkzCQjKYfc68L7jKjGlHMibw==", "cpu": [ "arm64" ], + "libc": [ + "musl" + ], "license": "LGPL-3.0-or-later", "optional": true, "os": [ @@ -1534,12 +1555,15 @@ } }, "node_modules/@img/sharp-libvips-linuxmusl-x64": { - "version": "1.3.2", - "resolved": "https://registry.npmjs.org/@img/sharp-libvips-linuxmusl-x64/-/sharp-libvips-linuxmusl-x64-1.3.2.tgz", - "integrity": "sha512-m0lrLiUt+lBYnCFr8qV/65yMR4E/c7/wf78I5eKTdkEakFAlZ9QlzEM3QIhhAwVeUhLAHLcCq7a7Vszq/oFNZQ==", + "version": "1.3.3", + "resolved": "https://registry.npmjs.org/@img/sharp-libvips-linuxmusl-x64/-/sharp-libvips-linuxmusl-x64-1.3.3.tgz", + "integrity": "sha512-fj8Mv0HHfD1Rr+4I68+3agJynxDWtBFgicTbSOb9Bke6pIwzGcJ+RX/yHjmiEGFMCavY/dxvem7MyNaJF+wDiw==", "cpu": [ "x64" ], + "libc": [ + "musl" + ], "license": "LGPL-3.0-or-later", "optional": true, "os": [ @@ -1550,12 +1574,15 @@ } }, "node_modules/@img/sharp-linux-arm": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/@img/sharp-linux-arm/-/sharp-linux-arm-0.35.3.tgz", - "integrity": "sha512-affVWCTLooy8TSxbDx2qkzuDeaWLNVBA+P//FNBirHsXpP2fuBhk5AuboYUnrDnzoXes8GFjpTx0SBFOCRg+FA==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/@img/sharp-linux-arm/-/sharp-linux-arm-0.35.4.tgz", + "integrity": "sha512-7OAS8gI0EReKGVN2HssHlM6umJgxF5VI3xN0p9FA91p/YO+ou5hiNghLdZ5BEHztwaaK5+bLKRf8x/o2L2nk9A==", "cpu": [ "arm" ], + "libc": [ + "glibc" + ], "license": "Apache-2.0", "optional": true, "os": [ @@ -1568,16 +1595,19 @@ "url": "https://opencollective.com/libvips" }, "optionalDependencies": { - "@img/sharp-libvips-linux-arm": "1.3.2" + "@img/sharp-libvips-linux-arm": "1.3.3" } }, "node_modules/@img/sharp-linux-arm64": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/@img/sharp-linux-arm64/-/sharp-linux-arm64-0.35.3.tgz", - "integrity": "sha512-QgKDspHPnrU+GQ55XPhGwyhC8acLVOOSyAvo1oVfFmrIXLkDNmGWzAfDZ4xK8oSA1qBQrALcHX0G5UZni/SuFQ==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/@img/sharp-linux-arm64/-/sharp-linux-arm64-0.35.4.tgz", + "integrity": "sha512-De4jpEnAU8Hd5oT0j1G3uL4ZvTuipVMn7YC6vPaJhy6/7EwEae0SVAoBrUMYQbkLGDm85taVWwuPc1a44LTzCQ==", "cpu": [ "arm64" ], + "libc": [ + "glibc" + ], "license": "Apache-2.0", "optional": true, "os": [ @@ -1590,16 +1620,19 @@ "url": "https://opencollective.com/libvips" }, "optionalDependencies": { - "@img/sharp-libvips-linux-arm64": "1.3.2" + "@img/sharp-libvips-linux-arm64": "1.3.3" } }, "node_modules/@img/sharp-linux-ppc64": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/@img/sharp-linux-ppc64/-/sharp-linux-ppc64-0.35.3.tgz", - "integrity": "sha512-sMd8rDxmpLOwv/7N44klFjOD5DUO7FLdjiXDI0hoxYaf7Ar262dQIEkosE98bps+5HPLtp/EvNqeqQtOycP/IA==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/@img/sharp-linux-ppc64/-/sharp-linux-ppc64-0.35.4.tgz", + "integrity": "sha512-2oYZJeIl4kCcMGk4ouZVjnkCtFrpQFlNEtJ6GbxzhHQchwH0NH/qEb9ykmOl29dqwMq+JhFdZn+1ak2FKhI9fQ==", "cpu": [ "ppc64" ], + "libc": [ + "glibc" + ], "license": "Apache-2.0", "optional": true, "os": [ @@ -1612,16 +1645,19 @@ "url": "https://opencollective.com/libvips" }, "optionalDependencies": { - "@img/sharp-libvips-linux-ppc64": "1.3.2" + "@img/sharp-libvips-linux-ppc64": "1.3.3" } }, "node_modules/@img/sharp-linux-riscv64": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/@img/sharp-linux-riscv64/-/sharp-linux-riscv64-0.35.3.tgz", - "integrity": "sha512-0Eob78yjlYPfL5vMNWAW55l3R9Y6BQS/gOfe0ZcP9mEz9ohhKSt4im1hayiknXgf8AWrFqMvJcKIdmLmEe7yeQ==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/@img/sharp-linux-riscv64/-/sharp-linux-riscv64-0.35.4.tgz", + "integrity": "sha512-cPbNChoRURAWdebDIHSenxRpgEdy7JkPydSnUxRm9VvKD7m0/xVaR/8Fzlu81pk5nHEvHH87UZUA7cTtwnbJSA==", "cpu": [ "riscv64" ], + "libc": [ + "glibc" + ], "license": "Apache-2.0", "optional": true, "os": [ @@ -1634,16 +1670,19 @@ "url": "https://opencollective.com/libvips" }, "optionalDependencies": { - "@img/sharp-libvips-linux-riscv64": "1.3.2" + "@img/sharp-libvips-linux-riscv64": "1.3.3" } }, "node_modules/@img/sharp-linux-s390x": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/@img/sharp-linux-s390x/-/sharp-linux-s390x-0.35.3.tgz", - "integrity": "sha512-KgAxQ0DxpNOq1rG2t5cgTgShJFGSuU7XO45cqC+1NVOuZnP6tlgZRuSYOfNupGkHID0o3cJOsw4DVeJpMovcGw==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/@img/sharp-linux-s390x/-/sharp-linux-s390x-0.35.4.tgz", + "integrity": "sha512-RY0JFY8Fd6RonCBtHz+DvadaPkXDSI1AUn6yWL9TipqkZ1vY8w8evqdgyDFnkm4/K1ve1TvZiaePP5oSd4+WVQ==", "cpu": [ "s390x" ], + "libc": [ + "glibc" + ], "license": "Apache-2.0", "optional": true, "os": [ @@ -1656,16 +1695,19 @@ "url": "https://opencollective.com/libvips" }, "optionalDependencies": { - "@img/sharp-libvips-linux-s390x": "1.3.2" + "@img/sharp-libvips-linux-s390x": "1.3.3" } }, "node_modules/@img/sharp-linux-x64": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/@img/sharp-linux-x64/-/sharp-linux-x64-0.35.3.tgz", - "integrity": "sha512-8pqvxubL2PGdhlPy6GLqzDYMUjyRmKAwKHYKixpdJYBUK7PJ0C029XdsnpFIdgRZG68fZiGdHVWcKPvtiPB4cA==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/@img/sharp-linux-x64/-/sharp-linux-x64-0.35.4.tgz", + "integrity": "sha512-9qvvEAuk8k89TfWUoX2htWjbAMX8p+NxCppjpcg5k6xMsjhBQPTsoIh36h9Qde4WRuGpJeYnOjdosDn/cnv+OA==", "cpu": [ "x64" ], + "libc": [ + "glibc" + ], "license": "Apache-2.0", "optional": true, "os": [ @@ -1678,16 +1720,19 @@ "url": "https://opencollective.com/libvips" }, "optionalDependencies": { - "@img/sharp-libvips-linux-x64": "1.3.2" + "@img/sharp-libvips-linux-x64": "1.3.3" } }, "node_modules/@img/sharp-linuxmusl-arm64": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/@img/sharp-linuxmusl-arm64/-/sharp-linuxmusl-arm64-0.35.3.tgz", - "integrity": "sha512-Vz0iQjzzcSX3HCbfwFfCSG/9SCIqyO0mH2sXyiHaAYfBk0cRsCWXRyQYX0ovCK/PAQBbTzQ0dsPQHh5MAFL59w==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/@img/sharp-linuxmusl-arm64/-/sharp-linuxmusl-arm64-0.35.4.tgz", + "integrity": "sha512-KB5jxpfWQTr0nc3xdHtWChdbifHrBGsd2SM62Eyxrl8afikm+f5qGBU75SJIZBT/S1MC8XyacdlXBMSWq6OURA==", "cpu": [ "arm64" ], + "libc": [ + "musl" + ], "license": "Apache-2.0", "optional": true, "os": [ @@ -1700,16 +1745,19 @@ "url": "https://opencollective.com/libvips" }, "optionalDependencies": { - "@img/sharp-libvips-linuxmusl-arm64": "1.3.2" + "@img/sharp-libvips-linuxmusl-arm64": "1.3.3" } }, "node_modules/@img/sharp-linuxmusl-x64": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/@img/sharp-linuxmusl-x64/-/sharp-linuxmusl-x64-0.35.3.tgz", - "integrity": "sha512-6O1NPKcDVj9QEdg7Hx549EX8U0rp6yXQERqru6yRN7fGBn32UvIRJUlWnk+8xDCiG76hXVBbX82NZ/ZKr0euIg==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/@img/sharp-linuxmusl-x64/-/sharp-linuxmusl-x64-0.35.4.tgz", + "integrity": "sha512-f+eZJZIQNEEd26RPSW+76chwOf1XtA2Y/O+5ocVyLliHkeih3e+jhLVBdNTd2rS3IbNXK8+ug93Vf5ZXtF5Lxg==", "cpu": [ "x64" ], + "libc": [ + "musl" + ], "license": "Apache-2.0", "optional": true, "os": [ @@ -1722,17 +1770,17 @@ "url": "https://opencollective.com/libvips" }, "optionalDependencies": { - "@img/sharp-libvips-linuxmusl-x64": "1.3.2" + "@img/sharp-libvips-linuxmusl-x64": "1.3.3" } }, "node_modules/@img/sharp-wasm32": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/@img/sharp-wasm32/-/sharp-wasm32-0.35.3.tgz", - "integrity": "sha512-cZ0XkcYGpHZkqW6iCkqTcmUC0CD9DhD5d/qeZlZkfRBn6GnHniZXLUo5+9xw8Iv76YE6LQFN9YNBlKREcCG76w==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/@img/sharp-wasm32/-/sharp-wasm32-0.35.4.tgz", + "integrity": "sha512-zQnl4Kwp7Q6NHsENtU2T/00Zi+w3AQNwz3+UaTyVBy2FpXrzXzGjndpK61onhZjRtRpQXxCTeqw19bVyXOh7jA==", "license": "Apache-2.0 AND LGPL-3.0-or-later AND MIT", "optional": true, "dependencies": { - "@emnapi/runtime": "^1.11.1" + "@emnapi/runtime": "^1.11.3" }, "engines": { "node": ">=20.9.0" @@ -1741,17 +1789,27 @@ "url": "https://opencollective.com/libvips" } }, + "node_modules/@img/sharp-wasm32/node_modules/@emnapi/runtime": { + "version": "1.11.3", + "resolved": "https://registry.npmjs.org/@emnapi/runtime/-/runtime-1.11.3.tgz", + "integrity": "sha512-Xz4Tpyki7XyrpbUK1jR1AhdAdaXyhhY4lZ3neLodmhpuWfy2PAQN5B46sAiU4liOXGLkHypn/qU+jvfWSCYYLA==", + "license": "MIT", + "optional": true, + "dependencies": { + "tslib": "^2.4.0" + } + }, "node_modules/@img/sharp-webcontainers-wasm32": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/@img/sharp-webcontainers-wasm32/-/sharp-webcontainers-wasm32-0.35.3.tgz", - "integrity": "sha512-2rnq7bX3NzeR2T4YWgz8qiG4h3TSdMe+vN1iQXpJleSJ3SM5zQ8Fy2SyyXAWlbxpEZ2Y+Z4u1BePgJEYbSy80Q==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/@img/sharp-webcontainers-wasm32/-/sharp-webcontainers-wasm32-0.35.4.tgz", + "integrity": "sha512-ESfNkywmCfPNyaZjxooddJQiQ+l/nTpGEOGthxiLnIHXC/CmcBixnfwUleX9mCz9ovrUUvKMap/pm8RYbzfwaA==", "cpu": [ "wasm32" ], "license": "Apache-2.0", "optional": true, "dependencies": { - "@img/sharp-wasm32": "0.35.3" + "@img/sharp-wasm32": "0.35.4" }, "engines": { "node": ">=20.9.0" @@ -1761,9 +1819,9 @@ } }, "node_modules/@img/sharp-win32-arm64": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/@img/sharp-win32-arm64/-/sharp-win32-arm64-0.35.3.tgz", - "integrity": "sha512-4bPwFdMbeC4JQ8L8LOyWp6nsHcboP5fxkp6iPOXz2Vg49R42TuMs2whkJ5OAP4/Ul035qOzy0AecOF9VOscn4w==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/@img/sharp-win32-arm64/-/sharp-win32-arm64-0.35.4.tgz", + "integrity": "sha512-iNdlBX9gLVvqe2I3uIJSIKTq6wckP/DYxZtcqxm09x5Gi24DnFBmPAWZmr60ZyYMG0xlzo6goG3670ar+RXvRw==", "cpu": [ "arm64" ], @@ -1780,9 +1838,9 @@ } }, "node_modules/@img/sharp-win32-ia32": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/@img/sharp-win32-ia32/-/sharp-win32-ia32-0.35.3.tgz", - "integrity": "sha512-r53mXsBN6lFUDiST764SvgwUdHAqM4rPAiDzAmf4fLoB6X/rkfyTrLCg6+g17wJJiCmB3JYgHuUldCWUIRFSXw==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/@img/sharp-win32-ia32/-/sharp-win32-ia32-0.35.4.tgz", + "integrity": "sha512-kqRsbaa5CS6KHlpxnN7WhE6vAAugXyZButpRdvDWetlv6Qv4N9WTcrWzF7tXfB9T7MsoadqdI8hmwLq6UlLvtw==", "cpu": [ "ia32" ], @@ -1799,9 +1857,9 @@ } }, "node_modules/@img/sharp-win32-x64": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/@img/sharp-win32-x64/-/sharp-win32-x64-0.35.3.tgz", - "integrity": "sha512-D4y1vNeZrIIJCN+uHaWVtH86B+aCrdMYYjicy9pXHvbGZeGYLLSd3wdVuC37FxVXlU1ARsk84eKWfWMXGYEqvA==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/@img/sharp-win32-x64/-/sharp-win32-x64-0.35.4.tgz", + "integrity": "sha512-XtmnYhBcrORsJ4XJngyzr/EWP0hRZLAZRFaApdKuviyqF78+ylxh2y06ZmtULAMOnObJ3ucpN0AcwSWnMowTRg==", "cpu": [ "x64" ], @@ -7524,9 +7582,9 @@ } }, "node_modules/sharp": { - "version": "0.35.3", - "resolved": "https://registry.npmjs.org/sharp/-/sharp-0.35.3.tgz", - "integrity": "sha512-ej0zVHuZGHCiABXcNxeYhpRnPNPAcvbG8RMdBAhDAxLKkCRVSpK3Iyu7qbqw3JMzoj0REeM6f3tJLtVwl0023Q==", + "version": "0.35.4", + "resolved": "https://registry.npmjs.org/sharp/-/sharp-0.35.4.tgz", + "integrity": "sha512-n++8XWcj+jCOr2IOl7h8LbKnGBDY4aPbmprMONBNFdn0ImXqpGVv5zliDs0V9HbmbCQLpbuo2ej9rAoOQTvMDA==", "license": "Apache-2.0", "dependencies": { "@img/colour": "^1.1.0", @@ -7540,31 +7598,31 @@ "url": "https://opencollective.com/libvips" }, "optionalDependencies": { - "@img/sharp-darwin-arm64": "0.35.3", - "@img/sharp-darwin-x64": "0.35.3", - "@img/sharp-freebsd-wasm32": "0.35.3", - "@img/sharp-libvips-darwin-arm64": "1.3.2", - "@img/sharp-libvips-darwin-x64": "1.3.2", - "@img/sharp-libvips-linux-arm": "1.3.2", - "@img/sharp-libvips-linux-arm64": "1.3.2", - "@img/sharp-libvips-linux-ppc64": "1.3.2", - "@img/sharp-libvips-linux-riscv64": "1.3.2", - "@img/sharp-libvips-linux-s390x": "1.3.2", - "@img/sharp-libvips-linux-x64": "1.3.2", - "@img/sharp-libvips-linuxmusl-arm64": "1.3.2", - "@img/sharp-libvips-linuxmusl-x64": "1.3.2", - "@img/sharp-linux-arm": "0.35.3", - "@img/sharp-linux-arm64": "0.35.3", - "@img/sharp-linux-ppc64": "0.35.3", - "@img/sharp-linux-riscv64": "0.35.3", - "@img/sharp-linux-s390x": "0.35.3", - "@img/sharp-linux-x64": "0.35.3", - "@img/sharp-linuxmusl-arm64": "0.35.3", - "@img/sharp-linuxmusl-x64": "0.35.3", - "@img/sharp-webcontainers-wasm32": "0.35.3", - "@img/sharp-win32-arm64": "0.35.3", - "@img/sharp-win32-ia32": "0.35.3", - "@img/sharp-win32-x64": "0.35.3" + "@img/sharp-darwin-arm64": "0.35.4", + "@img/sharp-darwin-x64": "0.35.4", + "@img/sharp-freebsd-wasm32": "0.35.4", + "@img/sharp-libvips-darwin-arm64": "1.3.3", + "@img/sharp-libvips-darwin-x64": "1.3.3", + "@img/sharp-libvips-linux-arm": "1.3.3", + "@img/sharp-libvips-linux-arm64": "1.3.3", + "@img/sharp-libvips-linux-ppc64": "1.3.3", + "@img/sharp-libvips-linux-riscv64": "1.3.3", + "@img/sharp-libvips-linux-s390x": "1.3.3", + "@img/sharp-libvips-linux-x64": "1.3.3", + "@img/sharp-libvips-linuxmusl-arm64": "1.3.3", + "@img/sharp-libvips-linuxmusl-x64": "1.3.3", + "@img/sharp-linux-arm": "0.35.4", + "@img/sharp-linux-arm64": "0.35.4", + "@img/sharp-linux-ppc64": "0.35.4", + "@img/sharp-linux-riscv64": "0.35.4", + "@img/sharp-linux-s390x": "0.35.4", + "@img/sharp-linux-x64": "0.35.4", + "@img/sharp-linuxmusl-arm64": "0.35.4", + "@img/sharp-linuxmusl-x64": "0.35.4", + "@img/sharp-webcontainers-wasm32": "0.35.4", + "@img/sharp-win32-arm64": "0.35.4", + "@img/sharp-win32-ia32": "0.35.4", + "@img/sharp-win32-x64": "0.35.4" }, "peerDependenciesMeta": { "@types/node": { diff --git a/docs/package.json b/docs/package.json index 5ec2f53eab5..3440c146b96 100644 --- a/docs/package.json +++ b/docs/package.json @@ -31,7 +31,7 @@ "astro-mermaid": "^2.1.0", "mermaid": "^11.17.0", "pdfjs-dist": "^6.2.108", - "sharp": "^0.35.3", + "sharp": "^0.35.4", "starlight-blog": "^0.29.0", "starlight-changelogs": "^0.6.0", "starlight-links-validator": "^0.25.3", From cb85f363d9b4b63fe33a527558101efd7b4b5614 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Tue, 1 Sep 2026 15:52:28 +0000 Subject: [PATCH 2/9] Plan PR merge-readiness pass Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com> --- .github/aw/actions-lock.json | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/aw/actions-lock.json b/.github/aw/actions-lock.json index 2f3fef9c045..020fa066305 100644 --- a/.github/aw/actions-lock.json +++ b/.github/aw/actions-lock.json @@ -38,6 +38,11 @@ "version": "v6.1.0", "sha": "55cc8345863c7cc4c66a329aec7e433d2d1c52a9" }, + "actions/checkout@v6.0.2": { + "repo": "actions/checkout", + "version": "v6.0.2", + "sha": "de0fac2e4500dabe0009e67214ff5f5447ce83dd" + }, "actions/checkout@v7.0.1": { "repo": "actions/checkout", "version": "v7.0.1", From 0f679c59cd8cb92bb14c8a4c87694c97252d2bee Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Tue, 1 Sep 2026 15:53:40 +0000 Subject: [PATCH 3/9] Restore scoped dependency update Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com> --- .github/aw/actions-lock.json | 5 ----- 1 file changed, 5 deletions(-) diff --git a/.github/aw/actions-lock.json b/.github/aw/actions-lock.json index 020fa066305..2f3fef9c045 100644 --- a/.github/aw/actions-lock.json +++ b/.github/aw/actions-lock.json @@ -38,11 +38,6 @@ "version": "v6.1.0", "sha": "55cc8345863c7cc4c66a329aec7e433d2d1c52a9" }, - "actions/checkout@v6.0.2": { - "repo": "actions/checkout", - "version": "v6.0.2", - "sha": "de0fac2e4500dabe0009e67214ff5f5447ce83dd" - }, "actions/checkout@v7.0.1": { "repo": "actions/checkout", "version": "v7.0.1", From f0ecccdedb53e2d3806266420405a62c7b058496 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Tue, 1 Sep 2026 17:43:08 +0000 Subject: [PATCH 4/9] Plan final PR readiness pass Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com> --- .github/aw/actions-lock.json | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/aw/actions-lock.json b/.github/aw/actions-lock.json index 2f3fef9c045..020fa066305 100644 --- a/.github/aw/actions-lock.json +++ b/.github/aw/actions-lock.json @@ -38,6 +38,11 @@ "version": "v6.1.0", "sha": "55cc8345863c7cc4c66a329aec7e433d2d1c52a9" }, + "actions/checkout@v6.0.2": { + "repo": "actions/checkout", + "version": "v6.0.2", + "sha": "de0fac2e4500dabe0009e67214ff5f5447ce83dd" + }, "actions/checkout@v7.0.1": { "repo": "actions/checkout", "version": "v7.0.1", From b31f64e36187760caa67d10d6ebe4a991b836f99 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Tue, 1 Sep 2026 17:53:05 +0000 Subject: [PATCH 5/9] Sync generated action pins Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com> --- pkg/actionpins/data/action_pins.json | 5 +++++ pkg/workflow/data/action_pins.json | 5 +++++ 2 files changed, 10 insertions(+) diff --git a/pkg/actionpins/data/action_pins.json b/pkg/actionpins/data/action_pins.json index 2f3fef9c045..020fa066305 100644 --- a/pkg/actionpins/data/action_pins.json +++ b/pkg/actionpins/data/action_pins.json @@ -38,6 +38,11 @@ "version": "v6.1.0", "sha": "55cc8345863c7cc4c66a329aec7e433d2d1c52a9" }, + "actions/checkout@v6.0.2": { + "repo": "actions/checkout", + "version": "v6.0.2", + "sha": "de0fac2e4500dabe0009e67214ff5f5447ce83dd" + }, "actions/checkout@v7.0.1": { "repo": "actions/checkout", "version": "v7.0.1", diff --git a/pkg/workflow/data/action_pins.json b/pkg/workflow/data/action_pins.json index 2f3fef9c045..020fa066305 100644 --- a/pkg/workflow/data/action_pins.json +++ b/pkg/workflow/data/action_pins.json @@ -38,6 +38,11 @@ "version": "v6.1.0", "sha": "55cc8345863c7cc4c66a329aec7e433d2d1c52a9" }, + "actions/checkout@v6.0.2": { + "repo": "actions/checkout", + "version": "v6.0.2", + "sha": "de0fac2e4500dabe0009e67214ff5f5447ce83dd" + }, "actions/checkout@v7.0.1": { "repo": "actions/checkout", "version": "v7.0.1", From 109a0e618409297804d7173f195950e36b72d410 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Tue, 1 Sep 2026 19:32:40 +0000 Subject: [PATCH 6/9] Inspect PR merge readiness Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com> --- pkg/workflow/schemas/github-workflow.json | 1116 +++++++++++---------- 1 file changed, 593 insertions(+), 523 deletions(-) diff --git a/pkg/workflow/schemas/github-workflow.json b/pkg/workflow/schemas/github-workflow.json index c0130091534..23083e8951d 100644 --- a/pkg/workflow/schemas/github-workflow.json +++ b/pkg/workflow/schemas/github-workflow.json @@ -405,13 +405,13 @@ "eventObject": { "oneOf": [ { - "type": "object" + "type": "object", + "additionalProperties": true }, { "type": "null" } - ], - "additionalProperties": true + ] }, "expressionSyntax": { "$comment": "escape `{` and `}` in pattern to be unicode compatible (#1360)", @@ -495,21 +495,45 @@ }, "oneOf": [ { + "type": "object", + "properties": { + "uses": true + }, "required": ["uses"] }, { + "type": "object", + "properties": { + "run": true + }, "required": ["run"] }, { + "type": "object", + "properties": { + "wait": true + }, "required": ["wait"] }, { + "type": "object", + "properties": { + "wait-all": true + }, "required": ["wait-all"] }, { + "type": "object", + "properties": { + "cancel": true + }, "required": ["cancel"] }, { + "type": "object", + "properties": { + "parallel": true + }, "required": ["parallel"] } ], @@ -522,7 +546,17 @@ "if": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstepsif", "description": "You can use the if conditional to prevent a step from running unless a condition is met. You can use any supported context and expression to create a conditional.\nExpressions in an if conditional do not require the ${{ }} syntax. For more information, see https://help.github.com/en/articles/contexts-and-expression-syntax-for-github-actions.", - "type": ["boolean", "number", "string"] + "anyOf": [ + { + "type": "boolean" + }, + { + "type": "number" + }, + { + "type": "string" + } + ] }, "name": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstepsname", @@ -549,16 +583,24 @@ "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstepswith", "$ref": "#/definitions/env", "description": "A map of the input parameters defined by the action. Each input parameter is a key/value pair. Input parameters are set as environment variables. The variable is prefixed with INPUT_ and converted to upper case.", - "properties": { - "args": { - "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstepswithargs", - "type": "string" + "anyOf": [ + { + "$ref": "#/definitions/env" }, - "entrypoint": { - "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstepswithentrypoint", - "type": "string" + { + "type": "object", + "properties": { + "args": { + "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstepswithargs", + "type": "string" + }, + "entrypoint": { + "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstepswithentrypoint", + "type": "string" + } + } } - } + ] }, "env": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstepsenv", @@ -614,7 +656,14 @@ "wait-all": { "$comment": "https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#jobsjob_idstepswait-all", "description": "Pauses the job until all active background steps complete. The wait-all keyword takes no arguments.", - "type": ["boolean", "null"] + "anyOf": [ + { + "type": "boolean" + }, + { + "type": "null" + } + ] }, "cancel": { "$comment": "https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#jobsjob_idstepscancel", @@ -732,7 +781,17 @@ "if": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idif", "description": "You can use the if conditional to prevent a job from running unless a condition is met. You can use any supported context and expression to create a conditional.\nExpressions in an if conditional do not require the ${{ }} syntax. For more information, see https://help.github.com/en/articles/contexts-and-expression-syntax-for-github-actions.", - "type": ["boolean", "number", "string"] + "anyOf": [ + { + "type": "boolean" + }, + { + "type": "number" + }, + { + "type": "string" + } + ] }, "uses": { "$comment": "https://docs.github.com/en/actions/learn-github-actions/workflow-syntax-for-github-actions#jobsjob_iduses", @@ -769,13 +828,27 @@ "fail-fast": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstrategyfail-fast", "description": "When set to true, GitHub cancels all in-progress jobs if any matrix job fails. Default: true", - "type": ["boolean", "string"], + "anyOf": [ + { + "type": "boolean" + }, + { + "type": "string" + } + ], "default": true }, "max-parallel": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstrategymax-parallel", "description": "The maximum number of jobs that can run simultaneously when using a matrix job strategy. By default, GitHub will maximize the number of jobs run in parallel depending on the available runners on GitHub-hosted virtual machines.", - "type": ["number", "string"] + "anyOf": [ + { + "type": "number" + }, + { + "type": "string" + } + ] } }, "required": ["matrix"], @@ -829,15 +902,10 @@ "type": "array", "anyOf": [ { - "items": [ - { - "type": "string" - } - ], - "minItems": 1, - "additionalItems": { + "items": { "type": "string" - } + }, + "minItems": 1 } ] }, @@ -905,7 +973,17 @@ "if": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idif", "description": "You can use the if conditional to prevent a job from running unless a condition is met. You can use any supported context and expression to create a conditional.\nExpressions in an if conditional do not require the ${{ }} syntax. For more information, see https://help.github.com/en/articles/contexts-and-expression-syntax-for-github-actions.", - "type": ["boolean", "number", "string"] + "anyOf": [ + { + "type": "boolean" + }, + { + "type": "number" + }, + { + "type": "string" + } + ] }, "steps": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idsteps", @@ -940,13 +1018,27 @@ "fail-fast": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstrategyfail-fast", "description": "When set to true, GitHub cancels all in-progress jobs if any matrix job fails. Default: true", - "type": ["boolean", "string"], + "anyOf": [ + { + "type": "boolean" + }, + { + "type": "string" + } + ], "default": true }, "max-parallel": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstrategymax-parallel", "description": "The maximum number of jobs that can run simultaneously when using a matrix job strategy. By default, GitHub will maximize the number of jobs run in parallel depending on the available runners on GitHub-hosted virtual machines.", - "type": ["number", "string"] + "anyOf": [ + { + "type": "number" + }, + { + "type": "string" + } + ] } }, "required": ["matrix"], @@ -1039,87 +1131,66 @@ "minItems": 1 } }, - "allOf": [ + "oneOf": [ { - "if": { - "properties": { - "type": { - "const": "string" - } + "type": "object", + "properties": { + "type": { + "const": "string" }, - "required": ["type"] - }, - "then": { - "properties": { - "default": { - "type": "string" - } + "default": { + "type": "string" } - } + }, + "required": ["type"] }, { - "if": { - "properties": { - "type": { - "const": "boolean" - } + "type": "object", + "properties": { + "type": { + "const": "boolean" }, - "required": ["type"] - }, - "then": { - "properties": { - "default": { - "type": "boolean" - } + "default": { + "type": "boolean" } - } + }, + "required": ["type"] }, { - "if": { - "properties": { - "type": { - "const": "number" - } + "type": "object", + "properties": { + "type": { + "const": "number" }, - "required": ["type"] - }, - "then": { - "properties": { - "default": { - "type": "number" - } + "default": { + "type": "number" } - } + }, + "required": ["type"] }, { - "if": { - "properties": { - "type": { - "const": "environment" - } + "type": "object", + "properties": { + "type": { + "const": "environment" }, - "required": ["type"] - }, - "then": { - "properties": { - "default": { - "type": "string" - } + "default": { + "type": "string" } - } + }, + "required": ["type"] }, { - "if": { - "properties": { - "type": { - "const": "choice" - } + "type": "object", + "properties": { + "type": { + "const": "choice" }, - "required": ["type"] + "options": { + "$ref": "#/definitions/workflowDispatchInput/properties/options" + } }, - "then": { - "required": ["options"] - } + "required": ["type", "options"] } ], "additionalProperties": false @@ -1150,415 +1221,396 @@ "properties": { "branch_protection_rule": { "$comment": "https://docs.github.com/en/actions/learn-github-actions/events-that-trigger-workflows#branch_protection_rule", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime the branch_protection_rule event occurs. More than one activity type triggers this event.", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["created", "edited", "deleted"] + }, + "default": ["created", "edited", "deleted"] } - ], - "items": { - "type": "string", - "enum": ["created", "edited", "deleted"] - }, - "default": ["created", "edited", "deleted"] + } } - } + ] }, "check_run": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#check-run-event-check_run", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime the check_run event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/checks/runs.", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["created", "rerequested", "completed", "requested_action"] + }, + "default": ["created", "rerequested", "completed", "requested_action"] } - ], - "items": { - "type": "string", - "enum": ["created", "rerequested", "completed", "requested_action"] - }, - "default": ["created", "rerequested", "completed", "requested_action"] + } } - } + ] }, "check_suite": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#check-suite-event-check_suite", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime the check_suite event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/checks/suites/.", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["completed", "requested", "rerequested"] + }, + "default": ["completed", "requested", "rerequested"] } - ], - "items": { - "type": "string", - "enum": ["completed", "requested", "rerequested"] - }, - "default": ["completed", "requested", "rerequested"] + } } - } + ] }, "create": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#create-event-create", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime someone creates a branch or tag, which triggers the create event. For information about the REST API, see https://developer.github.com/v3/git/refs/#create-a-reference." }, "delete": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#delete-event-delete", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime someone deletes a branch or tag, which triggers the delete event. For information about the REST API, see https://developer.github.com/v3/git/refs/#delete-a-reference." }, "deployment": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#deployment-event-deployment", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime someone creates a deployment, which triggers the deployment event. Deployments created with a commit SHA may not have a Git ref. For information about the REST API, see https://developer.github.com/v3/repos/deployments/." }, "deployment_status": { "$comment": "https://docs.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime a third party provides a deployment status, which triggers the deployment_status event. Deployments created with a commit SHA may not have a Git ref. For information about the REST API, see https://developer.github.com/v3/repos/deployments/#create-a-deployment-status." }, "discussion": { "$comment": "https://docs.github.com/en/actions/reference/events-that-trigger-workflows#discussion", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime the discussion event occurs. More than one activity type triggers this event. For information about the GraphQL API, see https://docs.github.com/en/graphql/guides/using-the-graphql-api-for-discussions", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["created", "edited", "deleted", "transferred", "pinned", "unpinned", "labeled", "unlabeled", "locked", "unlocked", "category_changed", "answered", "unanswered"] + }, + "default": ["created", "edited", "deleted", "transferred", "pinned", "unpinned", "labeled", "unlabeled", "locked", "unlocked", "category_changed", "answered", "unanswered"] } - ], - "items": { - "type": "string", - "enum": ["created", "edited", "deleted", "transferred", "pinned", "unpinned", "labeled", "unlabeled", "locked", "unlocked", "category_changed", "answered", "unanswered"] - }, - "default": ["created", "edited", "deleted", "transferred", "pinned", "unpinned", "labeled", "unlabeled", "locked", "unlocked", "category_changed", "answered", "unanswered"] + } } - } + ] }, "discussion_comment": { "$comment": "https://docs.github.com/en/actions/reference/events-that-trigger-workflows#discussion_comment", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime the discussion_comment event occurs. More than one activity type triggers this event. For information about the GraphQL API, see https://docs.github.com/en/graphql/guides/using-the-graphql-api-for-discussions", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" - } - ], - "items": { - "type": "string", - "enum": ["created", "edited", "deleted"] - }, - "default": ["created", "edited", "deleted"] - } - } + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["created", "edited", "deleted"] + }, + "default": ["created", "edited", "deleted"] + } + } + } + ] }, "fork": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#fork-event-fork", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime when someone forks a repository, which triggers the fork event. For information about the REST API, see https://developer.github.com/v3/repos/forks/#create-a-fork." }, "gollum": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#gollum-event-gollum", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow when someone creates or updates a Wiki page, which triggers the gollum event." }, "issue_comment": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#issue-comment-event-issue_comment", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime the issue_comment event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/issues/comments/.", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["created", "edited", "deleted"] + }, + "default": ["created", "edited", "deleted"] } - ], - "items": { - "type": "string", - "enum": ["created", "edited", "deleted"] - }, - "default": ["created", "edited", "deleted"] + } } - } + ] }, "issues": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#issues-event-issues", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime the issues event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/issues.", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": [ + "opened", + "edited", + "deleted", + "transferred", + "pinned", + "unpinned", + "closed", + "reopened", + "assigned", + "unassigned", + "labeled", + "unlabeled", + "locked", + "unlocked", + "milestoned", + "demilestoned", + "typed", + "untyped", + "field_added", + "field_removed" + ] + }, + "default": [ + "opened", + "edited", + "deleted", + "transferred", + "pinned", + "unpinned", + "closed", + "reopened", + "assigned", + "unassigned", + "labeled", + "unlabeled", + "locked", + "unlocked", + "milestoned", + "demilestoned", + "typed", + "untyped", + "field_added", + "field_removed" + ] } - ], - "items": { - "type": "string", - "enum": [ - "opened", - "edited", - "deleted", - "transferred", - "pinned", - "unpinned", - "closed", - "reopened", - "assigned", - "unassigned", - "labeled", - "unlabeled", - "locked", - "unlocked", - "milestoned", - "demilestoned", - "typed", - "untyped", - "field_added", - "field_removed" - ] - }, - "default": [ - "opened", - "edited", - "deleted", - "transferred", - "pinned", - "unpinned", - "closed", - "reopened", - "assigned", - "unassigned", - "labeled", - "unlabeled", - "locked", - "unlocked", - "milestoned", - "demilestoned", - "typed", - "untyped", - "field_added", - "field_removed" - ] + } } - } + ] }, "label": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#label-event-label", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime the label event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/issues/labels/.", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["created", "edited", "deleted"] + }, + "default": ["created", "edited", "deleted"] } - ], - "items": { - "type": "string", - "enum": ["created", "edited", "deleted"] - }, - "default": ["created", "edited", "deleted"] + } } - } + ] }, "merge_group": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#merge_group", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow when a pull request is added to a merge queue, which adds the pull request to a merge group. For information about the merge queue, see https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/incorporating-changes-from-a-pull-request/merging-a-pull-request-with-a-merge-queue .", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["checks_requested"] + }, + "default": ["checks_requested"] } - ], - "items": { - "type": "string", - "enum": ["checks_requested"] - }, - "default": ["checks_requested"] + } } - } + ] }, "milestone": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#milestone-event-milestone", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime the milestone event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/issues/milestones/.", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["created", "closed", "opened", "edited", "deleted"] + }, + "default": ["created", "closed", "opened", "edited", "deleted"] } - ], - "items": { - "type": "string", - "enum": ["created", "closed", "opened", "edited", "deleted"] - }, - "default": ["created", "closed", "opened", "edited", "deleted"] + } } - } + ] }, "page_build": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#page-build-event-page_build", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime someone pushes to a GitHub Pages-enabled branch, which triggers the page_build event. For information about the REST API, see https://developer.github.com/v3/repos/pages/." }, "project": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#project-event-project", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime the project event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/projects/.", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["created", "updated", "closed", "reopened", "edited", "deleted"] + }, + "default": ["created", "updated", "closed", "reopened", "edited", "deleted"] } - ], - "items": { - "type": "string", - "enum": ["created", "updated", "closed", "reopened", "edited", "deleted"] - }, - "default": ["created", "updated", "closed", "reopened", "edited", "deleted"] + } } - } + ] }, "project_card": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#project-card-event-project_card", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime the project_card event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/projects/cards.", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["created", "moved", "converted", "edited", "deleted"] + }, + "default": ["created", "moved", "converted", "edited", "deleted"] } - ], - "items": { - "type": "string", - "enum": ["created", "moved", "converted", "edited", "deleted"] - }, - "default": ["created", "moved", "converted", "edited", "deleted"] + } } - } + ] }, "project_column": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#project-column-event-project_column", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime the project_column event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/projects/columns.", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["created", "updated", "moved", "deleted"] + }, + "default": ["created", "updated", "moved", "deleted"] } - ], - "items": { - "type": "string", - "enum": ["created", "updated", "moved", "deleted"] - }, - "default": ["created", "updated", "moved", "deleted"] + } } - } + ] }, "public": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#public-event-public", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime someone makes a private repository public, which triggers the public event. For information about the REST API, see https://developer.github.com/v3/repos/#edit." }, "pull_request": { @@ -1574,11 +1626,8 @@ "type": "object", "properties": { "types": { - "allOf": [ - { - "$ref": "#/definitions/types" - } - ], + "$ref": "#/definitions/types", + "type": "array", "items": { "type": "string", "enum": [ @@ -1630,16 +1679,19 @@ }, { "not": { + "type": "object", "required": ["branches", "branches-ignore"] } }, { "not": { + "type": "object", "required": ["tags", "tags-ignore"] } }, { "not": { + "type": "object", "required": ["paths", "paths-ignore"] } } @@ -1649,49 +1701,51 @@ }, "pull_request_review": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#pull-request-review-event-pull_request_review", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime the pull_request_review event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/pulls/reviews.\nNote: Workflows do not run on private base repositories when you open a pull request from a forked repository.\nWhen you create a pull request from a forked repository to the base repository, GitHub sends the pull_request event to the base repository and no pull request events occur on the forked repository.\nWorkflows don't run on forked repositories by default. You must enable GitHub Actions in the Actions tab of the forked repository.\nThe permissions for the GITHUB_TOKEN in forked repositories is read-only. For more information about the GITHUB_TOKEN, see https://help.github.com/en/articles/virtual-environments-for-github-actions.", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["submitted", "edited", "dismissed"] + }, + "default": ["submitted", "edited", "dismissed"] } - ], - "items": { - "type": "string", - "enum": ["submitted", "edited", "dismissed"] - }, - "default": ["submitted", "edited", "dismissed"] + } } - } + ] }, "pull_request_review_comment": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#pull-request-review-comment-event-pull_request_review_comment", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime a comment on a pull request's unified diff is modified, which triggers the pull_request_review_comment event. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/pulls/comments.\nNote: Workflows do not run on private base repositories when you open a pull request from a forked repository.\nWhen you create a pull request from a forked repository to the base repository, GitHub sends the pull_request event to the base repository and no pull request events occur on the forked repository.\nWorkflows don't run on forked repositories by default. You must enable GitHub Actions in the Actions tab of the forked repository.\nThe permissions for the GITHUB_TOKEN in forked repositories is read-only. For more information about the GITHUB_TOKEN, see https://help.github.com/en/articles/virtual-environments-for-github-actions.", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["created", "edited", "deleted"] + }, + "default": ["created", "edited", "deleted"] } - ], - "items": { - "type": "string", - "enum": ["created", "edited", "deleted"] - }, - "default": ["created", "edited", "deleted"] + } } - } + ] }, "pull_request_target": { "$comment": "https://docs.github.com/en/actions/reference/events-that-trigger-workflows#pull_request_target", @@ -1706,11 +1760,8 @@ "type": "object", "properties": { "types": { - "allOf": [ - { - "$ref": "#/definitions/types" - } - ], + "$ref": "#/definitions/types", + "type": "array", "items": { "type": "string", "enum": [ @@ -1758,16 +1809,19 @@ }, { "not": { + "type": "object", "required": ["branches", "branches-ignore"] } }, { "not": { + "type": "object", "required": ["tags", "tags-ignore"] } }, { "not": { + "type": "object", "required": ["paths", "paths-ignore"] } } @@ -1810,16 +1864,19 @@ }, { "not": { + "type": "object", "required": ["branches", "branches-ignore"] } }, { "not": { + "type": "object", "required": ["tags", "tags-ignore"] } }, { "not": { + "type": "object", "required": ["paths", "paths-ignore"] } } @@ -1829,70 +1886,65 @@ }, "registry_package": { "$comment": "https://help.github.com/en/actions/reference/events-that-trigger-workflows#registry-package-event-registry_package", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime a package is published or updated. For more information, see https://help.github.com/en/github/managing-packages-with-github-packages.", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["published", "updated"] + }, + "default": ["published", "updated"] } - ], - "items": { - "type": "string", - "enum": ["published", "updated"] - }, - "default": ["published", "updated"] + } } - } + ] }, "release": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#release-event-release", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime the release event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/repos/releases/ in the GitHub Developer documentation.", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" + "oneOf": [ + { + "type": "null" + }, + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["published", "unpublished", "created", "edited", "deleted", "prereleased", "released"] + }, + "default": ["published", "unpublished", "created", "edited", "deleted", "prereleased", "released"] } - ], - "items": { - "type": "string", - "enum": ["published", "unpublished", "created", "edited", "deleted", "prereleased", "released"] - }, - "default": ["published", "unpublished", "created", "edited", "deleted", "prereleased", "released"] + } } - } + ] }, "status": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#status-event-status", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime the status of a Git commit changes, which triggers the status event. For information about the REST API, see https://developer.github.com/v3/repos/statuses/." }, "watch": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#watch-event-watch", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "Runs your workflow anytime the watch event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/activity/starring/." }, "workflow_call": { "$comment": "https://docs.github.com/en/actions/learn-github-actions/events-that-trigger-workflows#workflow_call", + "type": "object", "description": "Allows workflows to be reused by other workflows.", "properties": { "inputs": { @@ -1924,7 +1976,17 @@ "default": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/metadata-syntax-for-github-actions#inputsinput_iddefault", "description": "The default value is used when an input parameter isn't specified in a workflow file.", - "type": ["boolean", "number", "string"] + "anyOf": [ + { + "type": "boolean" + }, + { + "type": "number" + }, + { + "type": "string" + } + ] } }, "required": ["type"], @@ -1962,10 +2024,12 @@ }, "secrets": { "$comment": "https://docs.github.com/en/actions/learn-github-actions/workflow-syntax-for-github-actions#onworkflow_callsecrets", + "type": "object", "description": "A map of the secrets that can be used in the called workflow. Within the called workflow, you can use the secrets context to refer to a secret.", "patternProperties": { "^[_a-zA-Z][a-zA-Z0-9_-]*$": { "$comment": "https://docs.github.com/en/actions/learn-github-actions/workflow-syntax-for-github-actions#onworkflow_callsecretssecret_id", + "type": "object", "description": "A string identifier to associate with the secret.", "properties": { "description": { @@ -1987,62 +2051,68 @@ }, "workflow_dispatch": { "$comment": "https://github.blog/changelog/2020-07-06-github-actions-manual-triggers-with-workflow_dispatch/", + "$ref": "#/definitions/eventObject", "description": "You can now create workflows that are manually triggered with the new workflow_dispatch event. You will then see a 'Run workflow' button on the Actions tab, enabling you to easily trigger a run.", - "properties": { - "inputs": { - "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/metadata-syntax-for-github-actions#inputs", - "description": "Input parameters allow you to specify data that the action expects to use during runtime. GitHub stores input parameters as environment variables. Input ids with uppercase letters are converted to lowercase during runtime. We recommended using lowercase input ids.", + "oneOf": [ + { + "type": "null" + }, + { "type": "object", - "patternProperties": { - "^[_a-zA-Z][a-zA-Z0-9_-]*$": { - "$ref": "#/definitions/workflowDispatchInput" + "properties": { + "inputs": { + "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/metadata-syntax-for-github-actions#inputs", + "description": "Input parameters allow you to specify data that the action expects to use during runtime. GitHub stores input parameters as environment variables. Input ids with uppercase letters are converted to lowercase during runtime. We recommended using lowercase input ids.", + "type": "object", + "patternProperties": { + "^[_a-zA-Z][a-zA-Z0-9_-]*$": { + "$ref": "#/definitions/workflowDispatchInput" + } + }, + "additionalProperties": false } }, "additionalProperties": false } - }, - "additionalProperties": false + ] }, "workflow_run": { "$comment": "https://docs.github.com/en/actions/reference/events-that-trigger-workflows#workflow_run", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "This event occurs when a workflow run is requested or completed, and allows you to execute a workflow based on the finished result of another workflow. For example, if your pull_request workflow generates build artifacts, you can create a new workflow that uses workflow_run to analyze the results and add a comment to the original pull request.", - "properties": { - "types": { - "allOf": [ - { - "$ref": "#/definitions/types" - } - ], - "items": { - "type": "string", - "enum": ["requested", "completed", "in_progress"] - }, - "default": ["requested", "completed"] + "oneOf": [ + { + "type": "null" }, - "workflows": { - "type": "array", - "items": { - "type": "string" + { + "type": "object", + "properties": { + "types": { + "$ref": "#/definitions/types", + "type": "array", + "items": { + "type": "string", + "enum": ["requested", "completed", "in_progress"] + }, + "default": ["requested", "completed"] + }, + "workflows": { + "type": "array", + "items": { + "type": "string" + }, + "minItems": 1 + } }, - "minItems": 1 + "patternProperties": { + "^branches(-ignore)?$": {} + } } - }, - "patternProperties": { - "^branches(-ignore)?$": {} - } + ] }, "repository_dispatch": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#external-events-repository_dispatch", - "allOf": [ - { - "$ref": "#/definitions/eventObject" - } - ], + "$ref": "#/definitions/eventObject", "description": "You can use the GitHub API to trigger a webhook event called repository_dispatch when you want to trigger a workflow for activity that happens outside of GitHub. For more information, see https://developer.github.com/v3/repos/#create-a-repository-dispatch-event.\nTo trigger the custom repository_dispatch webhook event, you must send a POST request to a GitHub API endpoint and provide an event_type name to describe the activity type. To trigger a workflow run, you must also configure your workflow to use the repository_dispatch event." }, "schedule": { From b8f23d4c09dd6ea846d3f3e714fbe48d650f3af5 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Tue, 1 Sep 2026 19:33:49 +0000 Subject: [PATCH 7/9] Restore generated schema formatting Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com> --- pkg/workflow/schemas/github-workflow.json | 1114 ++++++++++----------- 1 file changed, 522 insertions(+), 592 deletions(-) diff --git a/pkg/workflow/schemas/github-workflow.json b/pkg/workflow/schemas/github-workflow.json index 23083e8951d..c0130091534 100644 --- a/pkg/workflow/schemas/github-workflow.json +++ b/pkg/workflow/schemas/github-workflow.json @@ -405,13 +405,13 @@ "eventObject": { "oneOf": [ { - "type": "object", - "additionalProperties": true + "type": "object" }, { "type": "null" } - ] + ], + "additionalProperties": true }, "expressionSyntax": { "$comment": "escape `{` and `}` in pattern to be unicode compatible (#1360)", @@ -495,45 +495,21 @@ }, "oneOf": [ { - "type": "object", - "properties": { - "uses": true - }, "required": ["uses"] }, { - "type": "object", - "properties": { - "run": true - }, "required": ["run"] }, { - "type": "object", - "properties": { - "wait": true - }, "required": ["wait"] }, { - "type": "object", - "properties": { - "wait-all": true - }, "required": ["wait-all"] }, { - "type": "object", - "properties": { - "cancel": true - }, "required": ["cancel"] }, { - "type": "object", - "properties": { - "parallel": true - }, "required": ["parallel"] } ], @@ -546,17 +522,7 @@ "if": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstepsif", "description": "You can use the if conditional to prevent a step from running unless a condition is met. You can use any supported context and expression to create a conditional.\nExpressions in an if conditional do not require the ${{ }} syntax. For more information, see https://help.github.com/en/articles/contexts-and-expression-syntax-for-github-actions.", - "anyOf": [ - { - "type": "boolean" - }, - { - "type": "number" - }, - { - "type": "string" - } - ] + "type": ["boolean", "number", "string"] }, "name": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstepsname", @@ -583,24 +549,16 @@ "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstepswith", "$ref": "#/definitions/env", "description": "A map of the input parameters defined by the action. Each input parameter is a key/value pair. Input parameters are set as environment variables. The variable is prefixed with INPUT_ and converted to upper case.", - "anyOf": [ - { - "$ref": "#/definitions/env" + "properties": { + "args": { + "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstepswithargs", + "type": "string" }, - { - "type": "object", - "properties": { - "args": { - "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstepswithargs", - "type": "string" - }, - "entrypoint": { - "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstepswithentrypoint", - "type": "string" - } - } + "entrypoint": { + "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstepswithentrypoint", + "type": "string" } - ] + } }, "env": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstepsenv", @@ -656,14 +614,7 @@ "wait-all": { "$comment": "https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#jobsjob_idstepswait-all", "description": "Pauses the job until all active background steps complete. The wait-all keyword takes no arguments.", - "anyOf": [ - { - "type": "boolean" - }, - { - "type": "null" - } - ] + "type": ["boolean", "null"] }, "cancel": { "$comment": "https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#jobsjob_idstepscancel", @@ -781,17 +732,7 @@ "if": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idif", "description": "You can use the if conditional to prevent a job from running unless a condition is met. You can use any supported context and expression to create a conditional.\nExpressions in an if conditional do not require the ${{ }} syntax. For more information, see https://help.github.com/en/articles/contexts-and-expression-syntax-for-github-actions.", - "anyOf": [ - { - "type": "boolean" - }, - { - "type": "number" - }, - { - "type": "string" - } - ] + "type": ["boolean", "number", "string"] }, "uses": { "$comment": "https://docs.github.com/en/actions/learn-github-actions/workflow-syntax-for-github-actions#jobsjob_iduses", @@ -828,27 +769,13 @@ "fail-fast": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstrategyfail-fast", "description": "When set to true, GitHub cancels all in-progress jobs if any matrix job fails. Default: true", - "anyOf": [ - { - "type": "boolean" - }, - { - "type": "string" - } - ], + "type": ["boolean", "string"], "default": true }, "max-parallel": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstrategymax-parallel", "description": "The maximum number of jobs that can run simultaneously when using a matrix job strategy. By default, GitHub will maximize the number of jobs run in parallel depending on the available runners on GitHub-hosted virtual machines.", - "anyOf": [ - { - "type": "number" - }, - { - "type": "string" - } - ] + "type": ["number", "string"] } }, "required": ["matrix"], @@ -902,10 +829,15 @@ "type": "array", "anyOf": [ { - "items": { + "items": [ + { + "type": "string" + } + ], + "minItems": 1, + "additionalItems": { "type": "string" - }, - "minItems": 1 + } } ] }, @@ -973,17 +905,7 @@ "if": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idif", "description": "You can use the if conditional to prevent a job from running unless a condition is met. You can use any supported context and expression to create a conditional.\nExpressions in an if conditional do not require the ${{ }} syntax. For more information, see https://help.github.com/en/articles/contexts-and-expression-syntax-for-github-actions.", - "anyOf": [ - { - "type": "boolean" - }, - { - "type": "number" - }, - { - "type": "string" - } - ] + "type": ["boolean", "number", "string"] }, "steps": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idsteps", @@ -1018,27 +940,13 @@ "fail-fast": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstrategyfail-fast", "description": "When set to true, GitHub cancels all in-progress jobs if any matrix job fails. Default: true", - "anyOf": [ - { - "type": "boolean" - }, - { - "type": "string" - } - ], + "type": ["boolean", "string"], "default": true }, "max-parallel": { "$comment": "https://help.github.com/en/actions/automating-your-workflow-with-github-actions/workflow-syntax-for-github-actions#jobsjob_idstrategymax-parallel", "description": "The maximum number of jobs that can run simultaneously when using a matrix job strategy. By default, GitHub will maximize the number of jobs run in parallel depending on the available runners on GitHub-hosted virtual machines.", - "anyOf": [ - { - "type": "number" - }, - { - "type": "string" - } - ] + "type": ["number", "string"] } }, "required": ["matrix"], @@ -1131,66 +1039,87 @@ "minItems": 1 } }, - "oneOf": [ + "allOf": [ { - "type": "object", - "properties": { - "type": { - "const": "string" + "if": { + "properties": { + "type": { + "const": "string" + } }, - "default": { - "type": "string" - } + "required": ["type"] }, - "required": ["type"] + "then": { + "properties": { + "default": { + "type": "string" + } + } + } }, { - "type": "object", - "properties": { - "type": { - "const": "boolean" + "if": { + "properties": { + "type": { + "const": "boolean" + } }, - "default": { - "type": "boolean" - } + "required": ["type"] }, - "required": ["type"] + "then": { + "properties": { + "default": { + "type": "boolean" + } + } + } }, { - "type": "object", - "properties": { - "type": { - "const": "number" + "if": { + "properties": { + "type": { + "const": "number" + } }, - "default": { - "type": "number" - } + "required": ["type"] }, - "required": ["type"] + "then": { + "properties": { + "default": { + "type": "number" + } + } + } }, { - "type": "object", - "properties": { - "type": { - "const": "environment" + "if": { + "properties": { + "type": { + "const": "environment" + } }, - "default": { - "type": "string" - } + "required": ["type"] }, - "required": ["type"] + "then": { + "properties": { + "default": { + "type": "string" + } + } + } }, { - "type": "object", - "properties": { - "type": { - "const": "choice" + "if": { + "properties": { + "type": { + "const": "choice" + } }, - "options": { - "$ref": "#/definitions/workflowDispatchInput/properties/options" - } + "required": ["type"] }, - "required": ["type", "options"] + "then": { + "required": ["options"] + } } ], "additionalProperties": false @@ -1221,396 +1150,415 @@ "properties": { "branch_protection_rule": { "$comment": "https://docs.github.com/en/actions/learn-github-actions/events-that-trigger-workflows#branch_protection_rule", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow anytime the branch_protection_rule event occurs. More than one activity type triggers this event.", - "oneOf": [ + "allOf": [ { - "type": "null" - }, - { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["created", "edited", "deleted"] - }, - "default": ["created", "edited", "deleted"] + "$ref": "#/definitions/eventObject" + } + ], + "description": "Runs your workflow anytime the branch_protection_rule event occurs. More than one activity type triggers this event.", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } - } + ], + "items": { + "type": "string", + "enum": ["created", "edited", "deleted"] + }, + "default": ["created", "edited", "deleted"] } - ] + } }, "check_run": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#check-run-event-check_run", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow anytime the check_run event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/checks/runs.", - "oneOf": [ + "allOf": [ { - "type": "null" - }, - { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["created", "rerequested", "completed", "requested_action"] - }, - "default": ["created", "rerequested", "completed", "requested_action"] + "$ref": "#/definitions/eventObject" + } + ], + "description": "Runs your workflow anytime the check_run event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/checks/runs.", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } - } + ], + "items": { + "type": "string", + "enum": ["created", "rerequested", "completed", "requested_action"] + }, + "default": ["created", "rerequested", "completed", "requested_action"] } - ] + } }, "check_suite": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#check-suite-event-check_suite", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow anytime the check_suite event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/checks/suites/.", - "oneOf": [ + "allOf": [ { - "type": "null" - }, - { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["completed", "requested", "rerequested"] - }, - "default": ["completed", "requested", "rerequested"] + "$ref": "#/definitions/eventObject" + } + ], + "description": "Runs your workflow anytime the check_suite event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/checks/suites/.", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } - } + ], + "items": { + "type": "string", + "enum": ["completed", "requested", "rerequested"] + }, + "default": ["completed", "requested", "rerequested"] } - ] + } }, "create": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#create-event-create", - "$ref": "#/definitions/eventObject", + "allOf": [ + { + "$ref": "#/definitions/eventObject" + } + ], "description": "Runs your workflow anytime someone creates a branch or tag, which triggers the create event. For information about the REST API, see https://developer.github.com/v3/git/refs/#create-a-reference." }, "delete": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#delete-event-delete", - "$ref": "#/definitions/eventObject", + "allOf": [ + { + "$ref": "#/definitions/eventObject" + } + ], "description": "Runs your workflow anytime someone deletes a branch or tag, which triggers the delete event. For information about the REST API, see https://developer.github.com/v3/git/refs/#delete-a-reference." }, "deployment": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#deployment-event-deployment", - "$ref": "#/definitions/eventObject", + "allOf": [ + { + "$ref": "#/definitions/eventObject" + } + ], "description": "Runs your workflow anytime someone creates a deployment, which triggers the deployment event. Deployments created with a commit SHA may not have a Git ref. For information about the REST API, see https://developer.github.com/v3/repos/deployments/." }, "deployment_status": { "$comment": "https://docs.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows", - "$ref": "#/definitions/eventObject", + "allOf": [ + { + "$ref": "#/definitions/eventObject" + } + ], "description": "Runs your workflow anytime a third party provides a deployment status, which triggers the deployment_status event. Deployments created with a commit SHA may not have a Git ref. For information about the REST API, see https://developer.github.com/v3/repos/deployments/#create-a-deployment-status." }, "discussion": { "$comment": "https://docs.github.com/en/actions/reference/events-that-trigger-workflows#discussion", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow anytime the discussion event occurs. More than one activity type triggers this event. For information about the GraphQL API, see https://docs.github.com/en/graphql/guides/using-the-graphql-api-for-discussions", - "oneOf": [ + "allOf": [ { - "type": "null" - }, - { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["created", "edited", "deleted", "transferred", "pinned", "unpinned", "labeled", "unlabeled", "locked", "unlocked", "category_changed", "answered", "unanswered"] - }, - "default": ["created", "edited", "deleted", "transferred", "pinned", "unpinned", "labeled", "unlabeled", "locked", "unlocked", "category_changed", "answered", "unanswered"] + "$ref": "#/definitions/eventObject" + } + ], + "description": "Runs your workflow anytime the discussion event occurs. More than one activity type triggers this event. For information about the GraphQL API, see https://docs.github.com/en/graphql/guides/using-the-graphql-api-for-discussions", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } - } + ], + "items": { + "type": "string", + "enum": ["created", "edited", "deleted", "transferred", "pinned", "unpinned", "labeled", "unlabeled", "locked", "unlocked", "category_changed", "answered", "unanswered"] + }, + "default": ["created", "edited", "deleted", "transferred", "pinned", "unpinned", "labeled", "unlabeled", "locked", "unlocked", "category_changed", "answered", "unanswered"] } - ] + } }, "discussion_comment": { "$comment": "https://docs.github.com/en/actions/reference/events-that-trigger-workflows#discussion_comment", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow anytime the discussion_comment event occurs. More than one activity type triggers this event. For information about the GraphQL API, see https://docs.github.com/en/graphql/guides/using-the-graphql-api-for-discussions", - "oneOf": [ + "allOf": [ { - "type": "null" - }, - { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["created", "edited", "deleted"] - }, - "default": ["created", "edited", "deleted"] - } - } + "$ref": "#/definitions/eventObject" } - ] + ], + "description": "Runs your workflow anytime the discussion_comment event occurs. More than one activity type triggers this event. For information about the GraphQL API, see https://docs.github.com/en/graphql/guides/using-the-graphql-api-for-discussions", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" + } + ], + "items": { + "type": "string", + "enum": ["created", "edited", "deleted"] + }, + "default": ["created", "edited", "deleted"] + } + } }, "fork": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#fork-event-fork", - "$ref": "#/definitions/eventObject", + "allOf": [ + { + "$ref": "#/definitions/eventObject" + } + ], "description": "Runs your workflow anytime when someone forks a repository, which triggers the fork event. For information about the REST API, see https://developer.github.com/v3/repos/forks/#create-a-fork." }, "gollum": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#gollum-event-gollum", - "$ref": "#/definitions/eventObject", + "allOf": [ + { + "$ref": "#/definitions/eventObject" + } + ], "description": "Runs your workflow when someone creates or updates a Wiki page, which triggers the gollum event." }, "issue_comment": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#issue-comment-event-issue_comment", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow anytime the issue_comment event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/issues/comments/.", - "oneOf": [ - { - "type": "null" - }, + "allOf": [ { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["created", "edited", "deleted"] - }, - "default": ["created", "edited", "deleted"] + "$ref": "#/definitions/eventObject" + } + ], + "description": "Runs your workflow anytime the issue_comment event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/issues/comments/.", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } - } + ], + "items": { + "type": "string", + "enum": ["created", "edited", "deleted"] + }, + "default": ["created", "edited", "deleted"] } - ] + } }, "issues": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#issues-event-issues", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow anytime the issues event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/issues.", - "oneOf": [ + "allOf": [ { - "type": "null" - }, - { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": [ - "opened", - "edited", - "deleted", - "transferred", - "pinned", - "unpinned", - "closed", - "reopened", - "assigned", - "unassigned", - "labeled", - "unlabeled", - "locked", - "unlocked", - "milestoned", - "demilestoned", - "typed", - "untyped", - "field_added", - "field_removed" - ] - }, - "default": [ - "opened", - "edited", - "deleted", - "transferred", - "pinned", - "unpinned", - "closed", - "reopened", - "assigned", - "unassigned", - "labeled", - "unlabeled", - "locked", - "unlocked", - "milestoned", - "demilestoned", - "typed", - "untyped", - "field_added", - "field_removed" - ] + "$ref": "#/definitions/eventObject" + } + ], + "description": "Runs your workflow anytime the issues event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/issues.", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } - } + ], + "items": { + "type": "string", + "enum": [ + "opened", + "edited", + "deleted", + "transferred", + "pinned", + "unpinned", + "closed", + "reopened", + "assigned", + "unassigned", + "labeled", + "unlabeled", + "locked", + "unlocked", + "milestoned", + "demilestoned", + "typed", + "untyped", + "field_added", + "field_removed" + ] + }, + "default": [ + "opened", + "edited", + "deleted", + "transferred", + "pinned", + "unpinned", + "closed", + "reopened", + "assigned", + "unassigned", + "labeled", + "unlabeled", + "locked", + "unlocked", + "milestoned", + "demilestoned", + "typed", + "untyped", + "field_added", + "field_removed" + ] } - ] + } }, "label": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#label-event-label", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow anytime the label event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/issues/labels/.", - "oneOf": [ + "allOf": [ { - "type": "null" - }, - { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["created", "edited", "deleted"] - }, - "default": ["created", "edited", "deleted"] + "$ref": "#/definitions/eventObject" + } + ], + "description": "Runs your workflow anytime the label event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/issues/labels/.", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } - } + ], + "items": { + "type": "string", + "enum": ["created", "edited", "deleted"] + }, + "default": ["created", "edited", "deleted"] } - ] + } }, "merge_group": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#merge_group", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow when a pull request is added to a merge queue, which adds the pull request to a merge group. For information about the merge queue, see https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/incorporating-changes-from-a-pull-request/merging-a-pull-request-with-a-merge-queue .", - "oneOf": [ - { - "type": "null" - }, + "allOf": [ { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["checks_requested"] - }, - "default": ["checks_requested"] + "$ref": "#/definitions/eventObject" + } + ], + "description": "Runs your workflow when a pull request is added to a merge queue, which adds the pull request to a merge group. For information about the merge queue, see https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/incorporating-changes-from-a-pull-request/merging-a-pull-request-with-a-merge-queue .", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } - } + ], + "items": { + "type": "string", + "enum": ["checks_requested"] + }, + "default": ["checks_requested"] } - ] + } }, "milestone": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#milestone-event-milestone", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow anytime the milestone event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/issues/milestones/.", - "oneOf": [ - { - "type": "null" - }, + "allOf": [ { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["created", "closed", "opened", "edited", "deleted"] - }, - "default": ["created", "closed", "opened", "edited", "deleted"] + "$ref": "#/definitions/eventObject" + } + ], + "description": "Runs your workflow anytime the milestone event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/issues/milestones/.", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } - } + ], + "items": { + "type": "string", + "enum": ["created", "closed", "opened", "edited", "deleted"] + }, + "default": ["created", "closed", "opened", "edited", "deleted"] } - ] + } }, "page_build": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#page-build-event-page_build", - "$ref": "#/definitions/eventObject", + "allOf": [ + { + "$ref": "#/definitions/eventObject" + } + ], "description": "Runs your workflow anytime someone pushes to a GitHub Pages-enabled branch, which triggers the page_build event. For information about the REST API, see https://developer.github.com/v3/repos/pages/." }, "project": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#project-event-project", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow anytime the project event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/projects/.", - "oneOf": [ + "allOf": [ { - "type": "null" - }, - { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["created", "updated", "closed", "reopened", "edited", "deleted"] - }, - "default": ["created", "updated", "closed", "reopened", "edited", "deleted"] + "$ref": "#/definitions/eventObject" + } + ], + "description": "Runs your workflow anytime the project event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/projects/.", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } - } + ], + "items": { + "type": "string", + "enum": ["created", "updated", "closed", "reopened", "edited", "deleted"] + }, + "default": ["created", "updated", "closed", "reopened", "edited", "deleted"] } - ] + } }, "project_card": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#project-card-event-project_card", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow anytime the project_card event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/projects/cards.", - "oneOf": [ + "allOf": [ { - "type": "null" - }, - { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["created", "moved", "converted", "edited", "deleted"] - }, - "default": ["created", "moved", "converted", "edited", "deleted"] + "$ref": "#/definitions/eventObject" + } + ], + "description": "Runs your workflow anytime the project_card event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/projects/cards.", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } - } + ], + "items": { + "type": "string", + "enum": ["created", "moved", "converted", "edited", "deleted"] + }, + "default": ["created", "moved", "converted", "edited", "deleted"] } - ] + } }, "project_column": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#project-column-event-project_column", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow anytime the project_column event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/projects/columns.", - "oneOf": [ - { - "type": "null" - }, + "allOf": [ { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["created", "updated", "moved", "deleted"] - }, - "default": ["created", "updated", "moved", "deleted"] + "$ref": "#/definitions/eventObject" + } + ], + "description": "Runs your workflow anytime the project_column event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/projects/columns.", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } - } + ], + "items": { + "type": "string", + "enum": ["created", "updated", "moved", "deleted"] + }, + "default": ["created", "updated", "moved", "deleted"] } - ] + } }, "public": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#public-event-public", - "$ref": "#/definitions/eventObject", + "allOf": [ + { + "$ref": "#/definitions/eventObject" + } + ], "description": "Runs your workflow anytime someone makes a private repository public, which triggers the public event. For information about the REST API, see https://developer.github.com/v3/repos/#edit." }, "pull_request": { @@ -1626,8 +1574,11 @@ "type": "object", "properties": { "types": { - "$ref": "#/definitions/types", - "type": "array", + "allOf": [ + { + "$ref": "#/definitions/types" + } + ], "items": { "type": "string", "enum": [ @@ -1679,19 +1630,16 @@ }, { "not": { - "type": "object", "required": ["branches", "branches-ignore"] } }, { "not": { - "type": "object", "required": ["tags", "tags-ignore"] } }, { "not": { - "type": "object", "required": ["paths", "paths-ignore"] } } @@ -1701,51 +1649,49 @@ }, "pull_request_review": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#pull-request-review-event-pull_request_review", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow anytime the pull_request_review event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/pulls/reviews.\nNote: Workflows do not run on private base repositories when you open a pull request from a forked repository.\nWhen you create a pull request from a forked repository to the base repository, GitHub sends the pull_request event to the base repository and no pull request events occur on the forked repository.\nWorkflows don't run on forked repositories by default. You must enable GitHub Actions in the Actions tab of the forked repository.\nThe permissions for the GITHUB_TOKEN in forked repositories is read-only. For more information about the GITHUB_TOKEN, see https://help.github.com/en/articles/virtual-environments-for-github-actions.", - "oneOf": [ - { - "type": "null" - }, + "allOf": [ { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["submitted", "edited", "dismissed"] - }, - "default": ["submitted", "edited", "dismissed"] + "$ref": "#/definitions/eventObject" + } + ], + "description": "Runs your workflow anytime the pull_request_review event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/pulls/reviews.\nNote: Workflows do not run on private base repositories when you open a pull request from a forked repository.\nWhen you create a pull request from a forked repository to the base repository, GitHub sends the pull_request event to the base repository and no pull request events occur on the forked repository.\nWorkflows don't run on forked repositories by default. You must enable GitHub Actions in the Actions tab of the forked repository.\nThe permissions for the GITHUB_TOKEN in forked repositories is read-only. For more information about the GITHUB_TOKEN, see https://help.github.com/en/articles/virtual-environments-for-github-actions.", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } - } + ], + "items": { + "type": "string", + "enum": ["submitted", "edited", "dismissed"] + }, + "default": ["submitted", "edited", "dismissed"] } - ] + } }, "pull_request_review_comment": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#pull-request-review-comment-event-pull_request_review_comment", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow anytime a comment on a pull request's unified diff is modified, which triggers the pull_request_review_comment event. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/pulls/comments.\nNote: Workflows do not run on private base repositories when you open a pull request from a forked repository.\nWhen you create a pull request from a forked repository to the base repository, GitHub sends the pull_request event to the base repository and no pull request events occur on the forked repository.\nWorkflows don't run on forked repositories by default. You must enable GitHub Actions in the Actions tab of the forked repository.\nThe permissions for the GITHUB_TOKEN in forked repositories is read-only. For more information about the GITHUB_TOKEN, see https://help.github.com/en/articles/virtual-environments-for-github-actions.", - "oneOf": [ - { - "type": "null" - }, + "allOf": [ { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["created", "edited", "deleted"] - }, - "default": ["created", "edited", "deleted"] + "$ref": "#/definitions/eventObject" + } + ], + "description": "Runs your workflow anytime a comment on a pull request's unified diff is modified, which triggers the pull_request_review_comment event. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/pulls/comments.\nNote: Workflows do not run on private base repositories when you open a pull request from a forked repository.\nWhen you create a pull request from a forked repository to the base repository, GitHub sends the pull_request event to the base repository and no pull request events occur on the forked repository.\nWorkflows don't run on forked repositories by default. You must enable GitHub Actions in the Actions tab of the forked repository.\nThe permissions for the GITHUB_TOKEN in forked repositories is read-only. For more information about the GITHUB_TOKEN, see https://help.github.com/en/articles/virtual-environments-for-github-actions.", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } - } + ], + "items": { + "type": "string", + "enum": ["created", "edited", "deleted"] + }, + "default": ["created", "edited", "deleted"] } - ] + } }, "pull_request_target": { "$comment": "https://docs.github.com/en/actions/reference/events-that-trigger-workflows#pull_request_target", @@ -1760,8 +1706,11 @@ "type": "object", "properties": { "types": { - "$ref": "#/definitions/types", - "type": "array", + "allOf": [ + { + "$ref": "#/definitions/types" + } + ], "items": { "type": "string", "enum": [ @@ -1809,19 +1758,16 @@ }, { "not": { - "type": "object", "required": ["branches", "branches-ignore"] } }, { "not": { - "type": "object", "required": ["tags", "tags-ignore"] } }, { "not": { - "type": "object", "required": ["paths", "paths-ignore"] } } @@ -1864,19 +1810,16 @@ }, { "not": { - "type": "object", "required": ["branches", "branches-ignore"] } }, { "not": { - "type": "object", "required": ["tags", "tags-ignore"] } }, { "not": { - "type": "object", "required": ["paths", "paths-ignore"] } } @@ -1886,65 +1829,70 @@ }, "registry_package": { "$comment": "https://help.github.com/en/actions/reference/events-that-trigger-workflows#registry-package-event-registry_package", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow anytime a package is published or updated. For more information, see https://help.github.com/en/github/managing-packages-with-github-packages.", - "oneOf": [ - { - "type": "null" - }, + "allOf": [ { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["published", "updated"] - }, - "default": ["published", "updated"] + "$ref": "#/definitions/eventObject" + } + ], + "description": "Runs your workflow anytime a package is published or updated. For more information, see https://help.github.com/en/github/managing-packages-with-github-packages.", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } - } + ], + "items": { + "type": "string", + "enum": ["published", "updated"] + }, + "default": ["published", "updated"] } - ] + } }, "release": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#release-event-release", - "$ref": "#/definitions/eventObject", - "description": "Runs your workflow anytime the release event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/repos/releases/ in the GitHub Developer documentation.", - "oneOf": [ - { - "type": "null" - }, + "allOf": [ { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["published", "unpublished", "created", "edited", "deleted", "prereleased", "released"] - }, - "default": ["published", "unpublished", "created", "edited", "deleted", "prereleased", "released"] + "$ref": "#/definitions/eventObject" + } + ], + "description": "Runs your workflow anytime the release event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/repos/releases/ in the GitHub Developer documentation.", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } - } + ], + "items": { + "type": "string", + "enum": ["published", "unpublished", "created", "edited", "deleted", "prereleased", "released"] + }, + "default": ["published", "unpublished", "created", "edited", "deleted", "prereleased", "released"] } - ] + } }, "status": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#status-event-status", - "$ref": "#/definitions/eventObject", + "allOf": [ + { + "$ref": "#/definitions/eventObject" + } + ], "description": "Runs your workflow anytime the status of a Git commit changes, which triggers the status event. For information about the REST API, see https://developer.github.com/v3/repos/statuses/." }, "watch": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#watch-event-watch", - "$ref": "#/definitions/eventObject", + "allOf": [ + { + "$ref": "#/definitions/eventObject" + } + ], "description": "Runs your workflow anytime the watch event occurs. More than one activity type triggers this event. For information about the REST API, see https://developer.github.com/v3/activity/starring/." }, "workflow_call": { "$comment": "https://docs.github.com/en/actions/learn-github-actions/events-that-trigger-workflows#workflow_call", - "type": "object", "description": "Allows workflows to be reused by other workflows.", "properties": { "inputs": { @@ -1976,17 +1924,7 @@ "default": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/metadata-syntax-for-github-actions#inputsinput_iddefault", "description": "The default value is used when an input parameter isn't specified in a workflow file.", - "anyOf": [ - { - "type": "boolean" - }, - { - "type": "number" - }, - { - "type": "string" - } - ] + "type": ["boolean", "number", "string"] } }, "required": ["type"], @@ -2024,12 +1962,10 @@ }, "secrets": { "$comment": "https://docs.github.com/en/actions/learn-github-actions/workflow-syntax-for-github-actions#onworkflow_callsecrets", - "type": "object", "description": "A map of the secrets that can be used in the called workflow. Within the called workflow, you can use the secrets context to refer to a secret.", "patternProperties": { "^[_a-zA-Z][a-zA-Z0-9_-]*$": { "$comment": "https://docs.github.com/en/actions/learn-github-actions/workflow-syntax-for-github-actions#onworkflow_callsecretssecret_id", - "type": "object", "description": "A string identifier to associate with the secret.", "properties": { "description": { @@ -2051,68 +1987,62 @@ }, "workflow_dispatch": { "$comment": "https://github.blog/changelog/2020-07-06-github-actions-manual-triggers-with-workflow_dispatch/", - "$ref": "#/definitions/eventObject", "description": "You can now create workflows that are manually triggered with the new workflow_dispatch event. You will then see a 'Run workflow' button on the Actions tab, enabling you to easily trigger a run.", - "oneOf": [ - { - "type": "null" - }, - { + "properties": { + "inputs": { + "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/metadata-syntax-for-github-actions#inputs", + "description": "Input parameters allow you to specify data that the action expects to use during runtime. GitHub stores input parameters as environment variables. Input ids with uppercase letters are converted to lowercase during runtime. We recommended using lowercase input ids.", "type": "object", - "properties": { - "inputs": { - "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/metadata-syntax-for-github-actions#inputs", - "description": "Input parameters allow you to specify data that the action expects to use during runtime. GitHub stores input parameters as environment variables. Input ids with uppercase letters are converted to lowercase during runtime. We recommended using lowercase input ids.", - "type": "object", - "patternProperties": { - "^[_a-zA-Z][a-zA-Z0-9_-]*$": { - "$ref": "#/definitions/workflowDispatchInput" - } - }, - "additionalProperties": false + "patternProperties": { + "^[_a-zA-Z][a-zA-Z0-9_-]*$": { + "$ref": "#/definitions/workflowDispatchInput" } }, "additionalProperties": false } - ] + }, + "additionalProperties": false }, "workflow_run": { "$comment": "https://docs.github.com/en/actions/reference/events-that-trigger-workflows#workflow_run", - "$ref": "#/definitions/eventObject", - "description": "This event occurs when a workflow run is requested or completed, and allows you to execute a workflow based on the finished result of another workflow. For example, if your pull_request workflow generates build artifacts, you can create a new workflow that uses workflow_run to analyze the results and add a comment to the original pull request.", - "oneOf": [ - { - "type": "null" - }, + "allOf": [ { - "type": "object", - "properties": { - "types": { - "$ref": "#/definitions/types", - "type": "array", - "items": { - "type": "string", - "enum": ["requested", "completed", "in_progress"] - }, - "default": ["requested", "completed"] - }, - "workflows": { - "type": "array", - "items": { - "type": "string" - }, - "minItems": 1 + "$ref": "#/definitions/eventObject" + } + ], + "description": "This event occurs when a workflow run is requested or completed, and allows you to execute a workflow based on the finished result of another workflow. For example, if your pull_request workflow generates build artifacts, you can create a new workflow that uses workflow_run to analyze the results and add a comment to the original pull request.", + "properties": { + "types": { + "allOf": [ + { + "$ref": "#/definitions/types" } + ], + "items": { + "type": "string", + "enum": ["requested", "completed", "in_progress"] }, - "patternProperties": { - "^branches(-ignore)?$": {} - } + "default": ["requested", "completed"] + }, + "workflows": { + "type": "array", + "items": { + "type": "string" + }, + "minItems": 1 } - ] + }, + "patternProperties": { + "^branches(-ignore)?$": {} + } }, "repository_dispatch": { "$comment": "https://help.github.com/en/github/automating-your-workflow-with-github-actions/events-that-trigger-workflows#external-events-repository_dispatch", - "$ref": "#/definitions/eventObject", + "allOf": [ + { + "$ref": "#/definitions/eventObject" + } + ], "description": "You can use the GitHub API to trigger a webhook event called repository_dispatch when you want to trigger a workflow for activity that happens outside of GitHub. For more information, see https://developer.github.com/v3/repos/#create-a-repository-dispatch-event.\nTo trigger the custom repository_dispatch webhook event, you must send a POST request to a GitHub API endpoint and provide an event_type name to describe the activity type. To trigger a workflow run, you must also configure your workflow to use the repository_dispatch event." }, "schedule": { From 69ed88d947518d4768b690f175ed83ed30b6c973 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Tue, 1 Sep 2026 21:55:41 +0000 Subject: [PATCH 8/9] Inspect final PR readiness Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com> --- .github/workflows/agent-job-health.lock.yml | 4 +- .../workflows/api-consumption-report.lock.yml | 8 +-- .github/workflows/archie.lock.yml | 2 +- .../workflows/architecture-guardian.lock.yml | 2 +- .github/workflows/audit-workflows.lock.yml | 8 +-- .github/workflows/blog-auditor.lock.yml | 2 +- .../breaking-change-checker.lock.yml | 2 +- .github/workflows/ci-coach.lock.yml | 4 +- .../claude-code-user-docs-review.lock.yml | 2 +- .github/workflows/cloclo.lock.yml | 4 +- .../workflows/code-scanning-fixer.lock.yml | 2 +- .github/workflows/code-simplifier.lock.yml | 2 +- .../workflows/copilot-agent-analysis.lock.yml | 6 +- .../copilot-pr-merged-report.lock.yml | 6 +- .../copilot-pr-nlp-analysis.lock.yml | 22 +++---- .../copilot-pr-prompt-analysis.lock.yml | 6 +- .../copilot-session-insights.lock.yml | 6 +- .../daily-architecture-diagram.lock.yml | 2 +- .../workflows/daily-cli-performance.lock.yml | 4 +- .../workflows/daily-cli-tools-tester.lock.yml | 2 +- .github/workflows/daily-code-metrics.lock.yml | 4 +- .../workflows/daily-compiler-quality.lock.yml | 4 +- ...ly-compiler-threat-spec-optimizer.lock.yml | 2 +- .github/workflows/daily-doc-healer.lock.yml | 2 +- .../daily-experiment-report.lock.yml | 2 +- .github/workflows/daily-file-diet.lock.yml | 4 +- .../daily-formal-spec-verifier.lock.yml | 2 +- .../workflows/daily-function-namer.lock.yml | 4 +- .../workflows/daily-geo-optimizer.lock.yml | 2 +- .../daily-graft-intelligence.lock.yml | 6 +- .../workflows/daily-issues-report.lock.yml | 66 +++++++++---------- .../daily-malicious-code-scan.lock.yml | 2 +- .../daily-mcp-concurrency-analysis.lock.yml | 2 +- .../daily-multi-device-docs-tester.lock.yml | 2 +- .github/workflows/daily-news.lock.yml | 6 +- .../daily-observability-report.lock.yml | 2 +- .../daily-performance-summary.lock.yml | 4 +- .github/workflows/daily-regulatory.lock.yml | 2 +- .../daily-reliability-review.lock.yml | 2 +- .../daily-rendering-scripts-verifier.lock.yml | 2 +- .../workflows/daily-repo-chronicle.lock.yml | 6 +- .../daily-safe-output-integrator.lock.yml | 2 +- .../daily-safe-output-optimizer.lock.yml | 2 +- .../daily-safe-outputs-conformance.lock.yml | 2 +- .../workflows/daily-secrets-analysis.lock.yml | 2 +- .../daily-security-observability.lock.yml | 20 +++--- .../daily-security-red-team.lock.yml | 2 +- .../daily-spdd-spec-planner.lock.yml | 2 +- .../daily-team-evolution-insights.lock.yml | 2 +- .../daily-testify-uber-super-expert.lock.yml | 4 +- .../daily-token-consumption-report.lock.yml | 2 +- .github/workflows/dead-code-remover.lock.yml | 2 +- .github/workflows/delight.lock.yml | 2 +- .github/workflows/dependabot-burner.lock.yml | 2 +- .../detection-analysis-report.lock.yml | 12 ++-- .../developer-docs-consolidator.lock.yml | 4 +- .github/workflows/docs-noob-tester.lock.yml | 4 +- .../duplicate-code-detector.lock.yml | 4 +- .github/workflows/eslint-refiner.lock.yml | 2 +- .../example-workflow-analyzer.lock.yml | 2 +- .../github-mcp-structural-analysis.lock.yml | 4 +- .../github-mcp-tools-report.lock.yml | 2 +- .../github-remote-mcp-auth-test.lock.yml | 2 +- .../workflows/glossary-maintainer.lock.yml | 4 +- .github/workflows/go-fan.lock.yml | 2 +- .github/workflows/grumpy-reviewer.lock.yml | 2 +- .../impeccable-skills-reviewer.lock.yml | 6 +- .github/workflows/linter-miner.lock.yml | 4 +- .github/workflows/lockfile-stats.lock.yml | 2 +- .../mattpocock-skills-reviewer.lock.yml | 4 +- .github/workflows/mcp-inspector.lock.yml | 8 +-- .github/workflows/ponytail-reviewer.lock.yml | 4 +- .github/workflows/portfolio-analyst.lock.yml | 2 +- .../pr-code-quality-reviewer.lock.yml | 4 +- .../workflows/pr-nitpick-reviewer.lock.yml | 4 +- .github/workflows/pr-triage-agent.lock.yml | 2 +- .../prompt-clustering-analysis.lock.yml | 30 ++++----- .github/workflows/purelock.lock.yml | 4 +- .github/workflows/python-data-charts.lock.yml | 4 +- .../workflows/refactoring-cadence.lock.yml | 2 +- .github/workflows/refiner.lock.yml | 4 +- .../workflows/repo-audit-analyzer.lock.yml | 2 +- .../repository-quality-improver.lock.yml | 4 +- .github/workflows/safe-output-health.lock.yml | 4 +- .../schema-consistency-checker.lock.yml | 2 +- .github/workflows/security-review.lock.yml | 4 +- .../semantic-function-refactor.lock.yml | 4 +- .github/workflows/sergo.lock.yml | 6 +- .github/workflows/skillet.lock.yml | 2 +- .../workflows/slide-deck-maintainer.lock.yml | 2 +- .github/workflows/smoke-codex.lock.yml | 8 +-- .../smoke-copilot-aoai-apikey.lock.yml | 4 +- .../smoke-copilot-aoai-entra.lock.yml | 14 ++-- .github/workflows/smoke-copilot-arm.lock.yml | 8 +-- .github/workflows/smoke-copilot.lock.yml | 4 +- .github/workflows/smoke-crush.lock.yml | 4 +- .github/workflows/smoke-cursor.lock.yml | 4 +- .../workflows/smoke-deepseek-harness.lock.yml | 4 +- .github/workflows/smoke-gemini.lock.yml | 4 +- .github/workflows/smoke-goose.lock.yml | 4 +- .github/workflows/smoke-kiro.lock.yml | 4 +- .github/workflows/smoke-opencode.lock.yml | 4 +- .github/workflows/smoke-pi.lock.yml | 4 +- .github/workflows/spec-extractor.lock.yml | 2 +- .github/workflows/spec-librarian.lock.yml | 2 +- .../workflows/stale-repo-identifier.lock.yml | 4 +- .github/workflows/terminal-stylist.lock.yml | 6 +- .github/workflows/typist.lock.yml | 4 +- .../workflows/ubuntu-image-analyzer.lock.yml | 2 +- .../uk-ai-operational-resilience.lock.yml | 2 +- .github/workflows/unbloat-docs.lock.yml | 2 +- .../workflows/weekly-issue-summary.lock.yml | 4 +- 112 files changed, 263 insertions(+), 263 deletions(-) diff --git a/.github/workflows/agent-job-health.lock.yml b/.github/workflows/agent-job-health.lock.yml index 1d6193c8624..3aa5b07ba6a 100644 --- a/.github/workflows/agent-job-health.lock.yml +++ b/.github/workflows/agent-job-health.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/aw-logs-24h-fetch.md -# - ../skills/jqschema/SKILL.md # - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md # - shared/daily-audit-base.md +# - shared/aw-logs-24h-fetch.md +# - ../skills/jqschema/SKILL.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/api-consumption-report.lock.yml b/.github/workflows/api-consumption-report.lock.yml index 84542fbd45e..d473f6ad01b 100644 --- a/.github/workflows/api-consumption-report.lock.yml +++ b/.github/workflows/api-consumption-report.lock.yml @@ -28,17 +28,17 @@ # Resolved workflow manifest: # Imports: # - shared/cache-memory-trending.md +# - shared/trending-charts-simple.md +# - shared/daily-audit-discussion.md # - ../skills/jqschema/SKILL.md # - shared/reporting.md # - shared/otlp.md -# - shared/trending-charts-simple.md +# - shared/daily-audit-base.md +# - shared/daily-audit-charts.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md # - shared/graders.md -# - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md -# - shared/daily-audit-charts.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/archie.lock.yml b/.github/workflows/archie.lock.yml index aa9dd6ddad5..697739bb37d 100644 --- a/.github/workflows/archie.lock.yml +++ b/.github/workflows/archie.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/architecture-guardian.lock.yml b/.github/workflows/architecture-guardian.lock.yml index 5b67cb2a06b..2cc2116a6b4 100644 --- a/.github/workflows/architecture-guardian.lock.yml +++ b/.github/workflows/architecture-guardian.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md +# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/audit-workflows.lock.yml b/.github/workflows/audit-workflows.lock.yml index 5acdb9fc04e..f39051185d0 100644 --- a/.github/workflows/audit-workflows.lock.yml +++ b/.github/workflows/audit-workflows.lock.yml @@ -27,19 +27,19 @@ # # Resolved workflow manifest: # Imports: +# - shared/trending-charts-simple.md +# - shared/daily-audit-discussion.md # - shared/repo-memory-standard.md # - ../skills/jqschema/SKILL.md # - shared/reporting.md # - shared/otlp.md +# - shared/daily-audit-base.md +# - shared/daily-audit-charts.md # - shared/default-ai-credits-pricing.md -# - shared/trending-charts-simple.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md # - shared/graders.md -# - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md -# - shared/daily-audit-charts.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/blog-auditor.lock.yml b/.github/workflows/blog-auditor.lock.yml index 851446197db..c58b7f62919 100644 --- a/.github/workflows/blog-auditor.lock.yml +++ b/.github/workflows/blog-auditor.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md diff --git a/.github/workflows/breaking-change-checker.lock.yml b/.github/workflows/breaking-change-checker.lock.yml index 49cbe967dd8..621f1bf7f51 100644 --- a/.github/workflows/breaking-change-checker.lock.yml +++ b/.github/workflows/breaking-change-checker.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md +# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/ci-coach.lock.yml b/.github/workflows/ci-coach.lock.yml index b738303a0a6..010b188539e 100644 --- a/.github/workflows/ci-coach.lock.yml +++ b/.github/workflows/ci-coach.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: +# - ../skills/jqschema/SKILL.md +# - shared/ci-data-analysis.md # - shared/ci-optimization-strategies.md # - shared/reporting.md # - shared/otlp.md -# - ../skills/jqschema/SKILL.md -# - shared/ci-data-analysis.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/claude-code-user-docs-review.lock.yml b/.github/workflows/claude-code-user-docs-review.lock.yml index a45b4100cfd..88bd1291338 100644 --- a/.github/workflows/claude-code-user-docs-review.lock.yml +++ b/.github/workflows/claude-code-user-docs-review.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md diff --git a/.github/workflows/cloclo.lock.yml b/.github/workflows/cloclo.lock.yml index cb5546ceb58..f04848a5049 100644 --- a/.github/workflows/cloclo.lock.yml +++ b/.github/workflows/cloclo.lock.yml @@ -27,10 +27,10 @@ # Resolved workflow manifest: # Imports: # - ../skills/jqschema/SKILL.md -# - shared/reporting.md -# - shared/otlp.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/reporting.md +# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/code-scanning-fixer.lock.yml b/.github/workflows/code-scanning-fixer.lock.yml index 2923ab916cf..887906c6cd5 100644 --- a/.github/workflows/code-scanning-fixer.lock.yml +++ b/.github/workflows/code-scanning-fixer.lock.yml @@ -30,10 +30,10 @@ # - shared/mcp-pagination.md # - shared/skip-if-issue-open.md # - shared/security-analysis-base.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md +# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/code-simplifier.lock.yml b/.github/workflows/code-simplifier.lock.yml index a88dc8af2f6..6a17975d7b1 100644 --- a/.github/workflows/code-simplifier.lock.yml +++ b/.github/workflows/code-simplifier.lock.yml @@ -29,10 +29,10 @@ # Imports: # - shared/mcp-pagination.md # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md +# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/copilot-agent-analysis.lock.yml b/.github/workflows/copilot-agent-analysis.lock.yml index 0f447572765..4f88e6cd95a 100644 --- a/.github/workflows/copilot-agent-analysis.lock.yml +++ b/.github/workflows/copilot-agent-analysis.lock.yml @@ -27,13 +27,13 @@ # # Resolved workflow manifest: # Imports: -# - shared/repo-memory-standard.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/daily-audit-base.md +# - shared/repo-memory-standard.md # - shared/copilot-pr-data-fetch.md # - shared/copilot-pr-analysis-base.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/copilot-pr-merged-report.lock.yml b/.github/workflows/copilot-pr-merged-report.lock.yml index 483fb7aee8d..9cada2408c0 100644 --- a/.github/workflows/copilot-pr-merged-report.lock.yml +++ b/.github/workflows/copilot-pr-merged-report.lock.yml @@ -28,12 +28,12 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md -# - shared/gh.md -# - shared/otlp.md # - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md +# - shared/gh.md # - shared/copilot-pr-data-fetch.md # - shared/copilot-pr-analysis-base.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/copilot-pr-nlp-analysis.lock.yml b/.github/workflows/copilot-pr-nlp-analysis.lock.yml index 599ab2e9b3c..ab3d83f3dd2 100644 --- a/.github/workflows/copilot-pr-nlp-analysis.lock.yml +++ b/.github/workflows/copilot-pr-nlp-analysis.lock.yml @@ -27,15 +27,15 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md # - shared/repo-memory-standard.md +# - shared/copilot-pr-data-fetch.md # - shared/python-dataviz.md # - shared/python-nlp.md # - shared/reporting.md +# - shared/copilot-pr-analysis-base.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md -# - shared/copilot-pr-data-fetch.md -# - shared/copilot-pr-analysis-base.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN @@ -541,6 +541,14 @@ jobs: MEMORY_DIR: /tmp/gh-aw/repo-memory/default CREATE_ORPHAN: true run: bash "${RUNNER_TEMP}/gh-aw/actions/clone_repo_memory_branch.sh" + - name: Install gh CLI + run: | + bash "${RUNNER_TEMP}/gh-aw/actions/install_gh_cli.sh" + - env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + name: Fetch Copilot PR data + run: "# Create output directories\nmkdir -p /tmp/gh-aw/agent/pr-data\nmkdir -p /tmp/gh-aw/cache-memory\n\n# Cache files use stable names so restored caches from previous runs are reusable\n# regardless of the date they were written on. Freshness is decided by file age.\nCACHE_DIR=\"/tmp/gh-aw/cache-memory\"\nCACHE_FILE=\"$CACHE_DIR/copilot-prs-latest.json\"\nCACHE_SCHEMA_FILE=\"$CACHE_DIR/copilot-prs-latest-schema.json\"\nCACHE_MAX_AGE_SECONDS=\"${CACHE_MAX_AGE_SECONDS:-21600}\"\n\n# Returns success when the file exists, is non-empty and younger than the max age.\ncache_is_fresh() {\n cache_path=\"$1\"\n [ -s \"$cache_path\" ] || return 1\n cache_mtime=$(date -r \"$cache_path\" '+%s' 2>/dev/null) || return 1\n [ -n \"$cache_mtime\" ] || return 1\n now=$(date '+%s')\n [ \"$((now - cache_mtime))\" -lt \"$CACHE_MAX_AGE_SECONDS\" ]\n}\n\n# Check if restored cache data is still fresh enough to reuse\nif cache_is_fresh \"$CACHE_FILE\"; then\n CACHE_AGE_MINUTES=$(( ( $(date '+%s') - $(date -r \"$CACHE_FILE\" '+%s') ) / 60 ))\n echo \"✓ Found cached PR data (${CACHE_AGE_MINUTES} minutes old)\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n \n # Regenerate schema if missing\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n \n echo \"Using cached data written ${CACHE_AGE_MINUTES} minutes ago\"\n echo \"Total PRs in cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nelse\n echo \"⬇ Downloading fresh PR data...\"\n \n # Calculate date 30 days ago\n DATE_30_DAYS_AGO=$(date -d '30 days ago' '+%Y-%m-%d' 2>/dev/null || date -v-30d '+%Y-%m-%d')\n\n # Search for PRs from copilot/* branches in the last 30 days using gh CLI\n # Using branch prefix search (head:copilot/) instead of author for reliability\n echo \"Fetching Copilot PRs from the last 30 days...\"\n FETCH_TMP=\"${RUNNER_TEMP:-/tmp}/copilot-prs-fetch.json\"\n rm -f \"$FETCH_TMP\"\n FETCH_OK=true\n gh pr list --repo \"$GITHUB_REPOSITORY\" \\\n --search \"head:copilot/ created:>=${DATE_30_DAYS_AGO}\" \\\n --state all \\\n --json number,title,author,headRefName,createdAt,state,url,body,labels,updatedAt,closedAt,mergedAt \\\n --limit 1000 \\\n > \"$FETCH_TMP\" || FETCH_OK=false\n\n if [ \"$FETCH_OK\" != \"true\" ] || ! jq -e 'type == \"array\"' \"$FETCH_TMP\" >/dev/null 2>&1; then\n # Transient GitHub API failures (e.g. 503) must not fail the whole run when\n # stale cached data is still available; fall back to it instead.\n if [ -s \"$CACHE_FILE\" ]; then\n echo \"::warning::Failed to fetch Copilot PR data; falling back to stale cached data\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n echo \"Total PRs in stale cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\n echo \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\n echo \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n exit 0\n fi\n echo \"::error::Failed to fetch Copilot PR data and no cached data is available\"\n exit 1\n fi\n\n cp \"$FETCH_TMP\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n rm -f \"$FETCH_TMP\"\n\n # Generate schema for reference\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n\n # Store in cache under stable names so future runs can reuse it on any date\n cp /tmp/gh-aw/agent/pr-data/copilot-prs.json \"$CACHE_FILE\"\n cp /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json \"$CACHE_SCHEMA_FILE\"\n\n # Drop legacy date-keyed cache entries so the cache does not grow unbounded\n rm -f \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9].json \\\n \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]-schema.json 2>/dev/null || true\n\n echo \"✓ PR data saved to cache: $(basename \"$CACHE_FILE\")\"\n echo \"Total PRs found: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nfi\n\n# Always ensure data is available at expected locations for backward compatibility\necho \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\necho \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n" - name: Setup Python environment run: "# Create working directory for Python scripts\nmkdir -p /tmp/gh-aw/python\nmkdir -p /tmp/gh-aw/python/data\nmkdir -p /tmp/gh-aw/python/charts\nmkdir -p /tmp/gh-aw/python/artifacts\n\necho \"Python environment setup complete\"\necho \"Working directory: /tmp/gh-aw/python\"\necho \"Data directory: /tmp/gh-aw/python/data\"\necho \"Charts directory: /tmp/gh-aw/python/charts\"\necho \"Artifacts directory: /tmp/gh-aw/python/artifacts\"\n" - env: @@ -561,14 +569,6 @@ jobs: UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python name: Setup Python NLP environment run: "mkdir -p /tmp/gh-aw/python/{data,charts,artifacts}\n# Create a virtual environment for proper package isolation (avoids --break-system-packages)\n# Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/)\n# Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC).\n# This must match shared/python-dataviz.md so either import can create the shared environment first.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/pip install --quiet nltk scikit-learn textblob wordcloud\n\n# Download required NLTK corpora\n/tmp/gh-aw/python/venv/bin/python3 -c \"\nimport nltk\nfor corpus in ['punkt_tab', 'stopwords', 'vader_lexicon', 'averaged_perceptron_tagger_eng']:\n nltk.download(corpus, quiet=True)\nprint('NLTK corpora ready')\n\"\n\n/tmp/gh-aw/python/venv/bin/python3 -c \"import sklearn; print(f'scikit-learn {sklearn.__version__}')\"\n" - - name: Install gh CLI - run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_gh_cli.sh" - - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Fetch Copilot PR data - run: "# Create output directories\nmkdir -p /tmp/gh-aw/agent/pr-data\nmkdir -p /tmp/gh-aw/cache-memory\n\n# Cache files use stable names so restored caches from previous runs are reusable\n# regardless of the date they were written on. Freshness is decided by file age.\nCACHE_DIR=\"/tmp/gh-aw/cache-memory\"\nCACHE_FILE=\"$CACHE_DIR/copilot-prs-latest.json\"\nCACHE_SCHEMA_FILE=\"$CACHE_DIR/copilot-prs-latest-schema.json\"\nCACHE_MAX_AGE_SECONDS=\"${CACHE_MAX_AGE_SECONDS:-21600}\"\n\n# Returns success when the file exists, is non-empty and younger than the max age.\ncache_is_fresh() {\n cache_path=\"$1\"\n [ -s \"$cache_path\" ] || return 1\n cache_mtime=$(date -r \"$cache_path\" '+%s' 2>/dev/null) || return 1\n [ -n \"$cache_mtime\" ] || return 1\n now=$(date '+%s')\n [ \"$((now - cache_mtime))\" -lt \"$CACHE_MAX_AGE_SECONDS\" ]\n}\n\n# Check if restored cache data is still fresh enough to reuse\nif cache_is_fresh \"$CACHE_FILE\"; then\n CACHE_AGE_MINUTES=$(( ( $(date '+%s') - $(date -r \"$CACHE_FILE\" '+%s') ) / 60 ))\n echo \"✓ Found cached PR data (${CACHE_AGE_MINUTES} minutes old)\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n \n # Regenerate schema if missing\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n \n echo \"Using cached data written ${CACHE_AGE_MINUTES} minutes ago\"\n echo \"Total PRs in cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nelse\n echo \"⬇ Downloading fresh PR data...\"\n \n # Calculate date 30 days ago\n DATE_30_DAYS_AGO=$(date -d '30 days ago' '+%Y-%m-%d' 2>/dev/null || date -v-30d '+%Y-%m-%d')\n\n # Search for PRs from copilot/* branches in the last 30 days using gh CLI\n # Using branch prefix search (head:copilot/) instead of author for reliability\n echo \"Fetching Copilot PRs from the last 30 days...\"\n FETCH_TMP=\"${RUNNER_TEMP:-/tmp}/copilot-prs-fetch.json\"\n rm -f \"$FETCH_TMP\"\n FETCH_OK=true\n gh pr list --repo \"$GITHUB_REPOSITORY\" \\\n --search \"head:copilot/ created:>=${DATE_30_DAYS_AGO}\" \\\n --state all \\\n --json number,title,author,headRefName,createdAt,state,url,body,labels,updatedAt,closedAt,mergedAt \\\n --limit 1000 \\\n > \"$FETCH_TMP\" || FETCH_OK=false\n\n if [ \"$FETCH_OK\" != \"true\" ] || ! jq -e 'type == \"array\"' \"$FETCH_TMP\" >/dev/null 2>&1; then\n # Transient GitHub API failures (e.g. 503) must not fail the whole run when\n # stale cached data is still available; fall back to it instead.\n if [ -s \"$CACHE_FILE\" ]; then\n echo \"::warning::Failed to fetch Copilot PR data; falling back to stale cached data\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n echo \"Total PRs in stale cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\n echo \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\n echo \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n exit 0\n fi\n echo \"::error::Failed to fetch Copilot PR data and no cached data is available\"\n exit 1\n fi\n\n cp \"$FETCH_TMP\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n rm -f \"$FETCH_TMP\"\n\n # Generate schema for reference\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n\n # Store in cache under stable names so future runs can reuse it on any date\n cp /tmp/gh-aw/agent/pr-data/copilot-prs.json \"$CACHE_FILE\"\n cp /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json \"$CACHE_SCHEMA_FILE\"\n\n # Drop legacy date-keyed cache entries so the cache does not grow unbounded\n rm -f \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9].json \\\n \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]-schema.json 2>/dev/null || true\n\n echo \"✓ PR data saved to cache: $(basename \"$CACHE_FILE\")\"\n echo \"Total PRs found: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nfi\n\n# Always ensure data is available at expected locations for backward compatibility\necho \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\necho \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/copilot-pr-prompt-analysis.lock.yml b/.github/workflows/copilot-pr-prompt-analysis.lock.yml index 70dada575a6..95de1212f6c 100644 --- a/.github/workflows/copilot-pr-prompt-analysis.lock.yml +++ b/.github/workflows/copilot-pr-prompt-analysis.lock.yml @@ -27,13 +27,13 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md # - shared/repo-memory-standard.md +# - shared/copilot-pr-data-fetch.md # - shared/reporting.md +# - shared/copilot-pr-analysis-base.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md -# - shared/copilot-pr-data-fetch.md -# - shared/copilot-pr-analysis-base.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/copilot-session-insights.lock.yml b/.github/workflows/copilot-session-insights.lock.yml index b6302bf7540..7ff426e1764 100644 --- a/.github/workflows/copilot-session-insights.lock.yml +++ b/.github/workflows/copilot-session-insights.lock.yml @@ -28,16 +28,16 @@ # Resolved workflow manifest: # Imports: # - shared/mcp-pagination.md +# - shared/daily-audit-discussion.md # - shared/repo-memory-standard.md # - ../skills/jqschema/SKILL.md # - shared/copilot-session-data-fetch.md +# - shared/python-dataviz.md +# - shared/session-analysis-charts.md # - shared/session-analysis-strategies.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md -# - shared/python-dataviz.md -# - shared/session-analysis-charts.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/daily-architecture-diagram.lock.yml b/.github/workflows/daily-architecture-diagram.lock.yml index 77040434559..f6594731b82 100644 --- a/.github/workflows/daily-architecture-diagram.lock.yml +++ b/.github/workflows/daily-architecture-diagram.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-cli-performance.lock.yml b/.github/workflows/daily-cli-performance.lock.yml index 63fe97aff14..6c51ac652a9 100644 --- a/.github/workflows/daily-cli-performance.lock.yml +++ b/.github/workflows/daily-cli-performance.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/mcp-pagination.md -# - shared/go-make.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/go-make.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-cli-tools-tester.lock.yml b/.github/workflows/daily-cli-tools-tester.lock.yml index f32a8c6682e..36351c15d14 100644 --- a/.github/workflows/daily-cli-tools-tester.lock.yml +++ b/.github/workflows/daily-cli-tools-tester.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-code-metrics.lock.yml b/.github/workflows/daily-code-metrics.lock.yml index b91bda9c45d..c06d3b8816b 100644 --- a/.github/workflows/daily-code-metrics.lock.yml +++ b/.github/workflows/daily-code-metrics.lock.yml @@ -28,12 +28,12 @@ # Resolved workflow manifest: # Imports: # - shared/crush.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/daily-audit-base.md # - shared/python-dataviz.md # - shared/trends.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - DOCKER_PAT diff --git a/.github/workflows/daily-compiler-quality.lock.yml b/.github/workflows/daily-compiler-quality.lock.yml index 868c1fc59a9..f3319009d5e 100644 --- a/.github/workflows/daily-compiler-quality.lock.yml +++ b/.github/workflows/daily-compiler-quality.lock.yml @@ -28,12 +28,12 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - DOCKER_PAT diff --git a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml index fcef34eac6b..7d1582c9078 100644 --- a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml +++ b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-doc-healer.lock.yml b/.github/workflows/daily-doc-healer.lock.yml index 7c89a9e09a1..337ce0a86ba 100644 --- a/.github/workflows/daily-doc-healer.lock.yml +++ b/.github/workflows/daily-doc-healer.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-experiment-report.lock.yml b/.github/workflows/daily-experiment-report.lock.yml index f5b9f656895..310d4c234c3 100644 --- a/.github/workflows/daily-experiment-report.lock.yml +++ b/.github/workflows/daily-experiment-report.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/trending-charts-simple.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # diff --git a/.github/workflows/daily-file-diet.lock.yml b/.github/workflows/daily-file-diet.lock.yml index 113e004e1ef..1325a4246c6 100644 --- a/.github/workflows/daily-file-diet.lock.yml +++ b/.github/workflows/daily-file-diet.lock.yml @@ -28,14 +28,14 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md -# - shared/safe-output-app.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md +# - shared/safe-output-app.md +# - shared/otlp.md # # Secrets used: # - DOCKER_PAT diff --git a/.github/workflows/daily-formal-spec-verifier.lock.yml b/.github/workflows/daily-formal-spec-verifier.lock.yml index f3430761a78..234530946cc 100644 --- a/.github/workflows/daily-formal-spec-verifier.lock.yml +++ b/.github/workflows/daily-formal-spec-verifier.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md +# - shared/otlp.md # # Secrets used: # - GH_AW_AGENT_TOKEN diff --git a/.github/workflows/daily-function-namer.lock.yml b/.github/workflows/daily-function-namer.lock.yml index c129a29b95a..976b1053481 100644 --- a/.github/workflows/daily-function-namer.lock.yml +++ b/.github/workflows/daily-function-namer.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/daily-geo-optimizer.lock.yml b/.github/workflows/daily-geo-optimizer.lock.yml index f203caa8260..122c9e0ca02 100644 --- a/.github/workflows/daily-geo-optimizer.lock.yml +++ b/.github/workflows/daily-geo-optimizer.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-graft-intelligence.lock.yml b/.github/workflows/daily-graft-intelligence.lock.yml index d3abd6c8d56..752ba70ef4a 100644 --- a/.github/workflows/daily-graft-intelligence.lock.yml +++ b/.github/workflows/daily-graft-intelligence.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/gh.md -# - shared/mcp/graft.md -# - shared/noop-reminder.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md +# - shared/gh.md +# - shared/mcp/graft.md +# - shared/noop-reminder.md # # Secrets used: # - GH_AW_DEFAULT_OTLP_HEADERS diff --git a/.github/workflows/daily-issues-report.lock.yml b/.github/workflows/daily-issues-report.lock.yml index 57067937b26..9ffa3affd4a 100644 --- a/.github/workflows/daily-issues-report.lock.yml +++ b/.github/workflows/daily-issues-report.lock.yml @@ -28,15 +28,15 @@ # Resolved workflow manifest: # Imports: # - shared/github-guard-policy.md +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - ../skills/jqschema/SKILL.md # - shared/issues-data-fetch.md +# - shared/python-dataviz.md +# - shared/trends.md # - shared/python-nlp.md # - shared/otlp.md -# - shared/daily-audit-discussion.md -# - shared/reporting.md # - shared/daily-audit-base.md -# - shared/python-dataviz.md -# - shared/trends.md # # Secrets used: # - COPILOT_GITHUB_TOKEN @@ -665,35 +665,6 @@ jobs: GITHUB_GRAPHQL_URL: https://localhost:18443/api/graphql GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} NODE_EXTRA_CA_CERTS: /tmp/gh-aw/proxy-logs/proxy-tls/ca.crt - - name: Setup Python NLP environment - run: | - mkdir -p /tmp/gh-aw/python/{data,charts,artifacts} - # Create a virtual environment for proper package isolation (avoids --break-system-packages) - # Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/) - # Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC). - # This must match shared/python-dataviz.md so either import can create the shared environment first. - if [ ! -d /tmp/gh-aw/python/venv ]; then - uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv - fi - echo "/tmp/gh-aw/python/venv/bin" >> "$GITHUB_PATH" - /tmp/gh-aw/python/venv/bin/pip install --quiet nltk scikit-learn textblob wordcloud - - # Download required NLTK corpora - /tmp/gh-aw/python/venv/bin/python3 -c " - import nltk - for corpus in ['punkt_tab', 'stopwords', 'vader_lexicon', 'averaged_perceptron_tagger_eng']: - nltk.download(corpus, quiet=True) - print('NLTK corpora ready') - " - - /tmp/gh-aw/python/venv/bin/python3 -c "import sklearn; print(f'scikit-learn {sklearn.__version__}')" - env: - GH_HOST: ${{ env.GH_HOST || 'github.com' }} - GH_REPO: ${{ github.repository }} - GITHUB_API_URL: https://localhost:18443/api/v3 - GITHUB_GRAPHQL_URL: https://localhost:18443/api/graphql - NODE_EXTRA_CA_CERTS: /tmp/gh-aw/proxy-logs/proxy-tls/ca.crt - UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python - name: Setup Python environment run: | # Create working directory for Python scripts @@ -756,6 +727,35 @@ jobs: /tmp/gh-aw/python/*.py /tmp/gh-aw/python/data/* retention-days: 30 + - name: Setup Python NLP environment + run: | + mkdir -p /tmp/gh-aw/python/{data,charts,artifacts} + # Create a virtual environment for proper package isolation (avoids --break-system-packages) + # Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/) + # Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC). + # This must match shared/python-dataviz.md so either import can create the shared environment first. + if [ ! -d /tmp/gh-aw/python/venv ]; then + uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv + fi + echo "/tmp/gh-aw/python/venv/bin" >> "$GITHUB_PATH" + /tmp/gh-aw/python/venv/bin/pip install --quiet nltk scikit-learn textblob wordcloud + + # Download required NLTK corpora + /tmp/gh-aw/python/venv/bin/python3 -c " + import nltk + for corpus in ['punkt_tab', 'stopwords', 'vader_lexicon', 'averaged_perceptron_tagger_eng']: + nltk.download(corpus, quiet=True) + print('NLTK corpora ready') + " + + /tmp/gh-aw/python/venv/bin/python3 -c "import sklearn; print(f'scikit-learn {sklearn.__version__}')" + env: + GH_HOST: ${{ env.GH_HOST || 'github.com' }} + GH_REPO: ${{ github.repository }} + GITHUB_API_URL: https://localhost:18443/api/v3 + GITHUB_GRAPHQL_URL: https://localhost:18443/api/graphql + NODE_EXTRA_CA_CERTS: /tmp/gh-aw/proxy-logs/proxy-tls/ca.crt + UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python - name: Configure Git credentials env: GITHUB_REPOSITORY: ${{ github.repository }} diff --git a/.github/workflows/daily-malicious-code-scan.lock.yml b/.github/workflows/daily-malicious-code-scan.lock.yml index 71512ac17f8..2cb7befd963 100644 --- a/.github/workflows/daily-malicious-code-scan.lock.yml +++ b/.github/workflows/daily-malicious-code-scan.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/security-analysis-base.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml index 1cd423c7ac3..ab004e8382b 100644 --- a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml +++ b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md +# - shared/daily-audit-discussion.md # - shared/safe-output-app.md # - shared/mcp/serena.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-multi-device-docs-tester.lock.yml b/.github/workflows/daily-multi-device-docs-tester.lock.yml index 585d151885a..4954d7b98c4 100644 --- a/.github/workflows/daily-multi-device-docs-tester.lock.yml +++ b/.github/workflows/daily-multi-device-docs-tester.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-news.lock.yml b/.github/workflows/daily-news.lock.yml index 1cdfe7232b1..3bbf9448469 100644 --- a/.github/workflows/daily-news.lock.yml +++ b/.github/workflows/daily-news.lock.yml @@ -30,12 +30,12 @@ # - shared/repo-memory-standard.md # - shared/mcp/tavily.md # - ../skills/jqschema/SKILL.md -# - shared/otlp.md -# - shared/reporting.md # - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md # - shared/python-dataviz.md # - shared/trends.md +# - shared/otlp.md +# - shared/reporting.md +# - shared/daily-audit-base.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/daily-observability-report.lock.yml b/.github/workflows/daily-observability-report.lock.yml index 7206e0d4228..4ce473a6ccb 100644 --- a/.github/workflows/daily-observability-report.lock.yml +++ b/.github/workflows/daily-observability-report.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/meta-analysis-base.md +# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-performance-summary.lock.yml b/.github/workflows/daily-performance-summary.lock.yml index f16529ceade..7ce38a27a55 100644 --- a/.github/workflows/daily-performance-summary.lock.yml +++ b/.github/workflows/daily-performance-summary.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: +# - shared/trending-charts-simple.md +# - shared/daily-audit-discussion.md # - shared/github-queries-mcp-script.md # - shared/reporting.md # - shared/otlp.md -# - shared/trending-charts-simple.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # diff --git a/.github/workflows/daily-regulatory.lock.yml b/.github/workflows/daily-regulatory.lock.yml index 2159e5d3e65..9b7eea027c2 100644 --- a/.github/workflows/daily-regulatory.lock.yml +++ b/.github/workflows/daily-regulatory.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md # - shared/github-queries-mcp-script.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-reliability-review.lock.yml b/.github/workflows/daily-reliability-review.lock.yml index bcc68e1d417..765eaf6bd4d 100644 --- a/.github/workflows/daily-reliability-review.lock.yml +++ b/.github/workflows/daily-reliability-review.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/opencode.md +# - shared/activation-app.md # - shared/sentry.md # - shared/mcp/sentry.md # - shared/reporting.md -# - shared/activation-app.md # - shared/daily-issue-base.md # # Secrets used: diff --git a/.github/workflows/daily-rendering-scripts-verifier.lock.yml b/.github/workflows/daily-rendering-scripts-verifier.lock.yml index dae56e9884f..98dab9c9342 100644 --- a/.github/workflows/daily-rendering-scripts-verifier.lock.yml +++ b/.github/workflows/daily-rendering-scripts-verifier.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/meta-analysis-base.md # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md # - shared/daily-audit-discussion.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-repo-chronicle.lock.yml b/.github/workflows/daily-repo-chronicle.lock.yml index 8ea362d807f..3b06e6ebc0a 100644 --- a/.github/workflows/daily-repo-chronicle.lock.yml +++ b/.github/workflows/daily-repo-chronicle.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/reporting.md # - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md # - shared/python-dataviz.md # - shared/trends.md +# - shared/otlp.md +# - shared/reporting.md +# - shared/daily-audit-base.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/daily-safe-output-integrator.lock.yml b/.github/workflows/daily-safe-output-integrator.lock.yml index 34a6eb540ea..193fe6757be 100644 --- a/.github/workflows/daily-safe-output-integrator.lock.yml +++ b/.github/workflows/daily-safe-output-integrator.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-safe-output-optimizer.lock.yml b/.github/workflows/daily-safe-output-optimizer.lock.yml index 8618a793fcc..7d5b34a33a7 100644 --- a/.github/workflows/daily-safe-output-optimizer.lock.yml +++ b/.github/workflows/daily-safe-output-optimizer.lock.yml @@ -31,9 +31,9 @@ # - shared/aw-logs-24h-fetch-setup.md # - shared/activation-app.md # - ../skills/jqschema/SKILL.md +# - shared/daily-audit-discussion.md # - shared/otlp.md # - shared/reporting.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-safe-outputs-conformance.lock.yml b/.github/workflows/daily-safe-outputs-conformance.lock.yml index 88b98e86620..7409fa056be 100644 --- a/.github/workflows/daily-safe-outputs-conformance.lock.yml +++ b/.github/workflows/daily-safe-outputs-conformance.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-secrets-analysis.lock.yml b/.github/workflows/daily-secrets-analysis.lock.yml index 35cfa61be32..2d7f2590e6e 100644 --- a/.github/workflows/daily-secrets-analysis.lock.yml +++ b/.github/workflows/daily-secrets-analysis.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md # - shared/otlp.md # - shared/reporting.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-security-observability.lock.yml b/.github/workflows/daily-security-observability.lock.yml index 745ae8987a8..efad2330095 100644 --- a/.github/workflows/daily-security-observability.lock.yml +++ b/.github/workflows/daily-security-observability.lock.yml @@ -28,11 +28,11 @@ # Resolved workflow manifest: # Imports: # - shared/meta-analysis-base.md -# - shared/python-dataviz.md -# - shared/otlp.md # - shared/trending-charts-simple.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/python-dataviz.md +# - shared/otlp.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # @@ -570,32 +570,32 @@ jobs: with: key: agentic-logs path: .github/aw/logs - - name: Setup Python environment - run: "# Create working directory for Python scripts\nmkdir -p /tmp/gh-aw/python\nmkdir -p /tmp/gh-aw/python/data\nmkdir -p /tmp/gh-aw/python/charts\nmkdir -p /tmp/gh-aw/python/artifacts\n\necho \"Python environment setup complete\"\necho \"Working directory: /tmp/gh-aw/python\"\necho \"Data directory: /tmp/gh-aw/python/data\"\necho \"Charts directory: /tmp/gh-aw/python/charts\"\necho \"Artifacts directory: /tmp/gh-aw/python/artifacts\"\n" - env: UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python - name: Install Python scientific libraries - run: "# Create a virtual environment for proper package isolation (avoids --break-system-packages)\n# Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/)\n# Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC).\n# This must match shared/python-nlp.md so either import can create the shared environment first.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/pip install --quiet numpy pandas matplotlib seaborn scipy\n\n# Verify installations\n/tmp/gh-aw/python/venv/bin/python3 -c \"import numpy; print(f'NumPy {numpy.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import pandas; print(f'Pandas {pandas.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import matplotlib; print(f'Matplotlib {matplotlib.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import seaborn; print(f'Seaborn {seaborn.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import scipy; print(f'SciPy {scipy.__version__} installed')\"\n\necho \"All scientific libraries installed successfully\"\n" + name: Setup Python environment + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/python/{data,charts,artifacts}\n# The agent sandbox cannot run the runner's CPython (glibc mismatch) and only ships\n# PyPy, which has no wheels for the chart libraries — installing them from inside the\n# sandbox builds NumPy/SciPy from source and exhausts the runner disk. Install a\n# portable uv-managed CPython plus the chart libraries under /tmp/gh-aw, which is\n# mounted read-write into the sandbox, so the agent can import them directly.\n# This must match shared/python-dataviz.md and shared/python-nlp.md so either import can\n# create the shared environment first; never recreate it, or a sibling import's packages\n# (for example the NLP libraries) would be discarded.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\nuv pip install --quiet --python /tmp/gh-aw/python/venv/bin/python numpy pandas matplotlib seaborn scipy\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/python -c \"import numpy,pandas,matplotlib,seaborn,scipy;print('chart-libraries-ready')\"\n" - if: always() name: Upload source files and data uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: if-no-files-found: warn - name: python-source-and-data + name: trending-source-and-data path: | /tmp/gh-aw/python/*.py /tmp/gh-aw/python/data/* retention-days: 30 + - name: Setup Python environment + run: "# Create working directory for Python scripts\nmkdir -p /tmp/gh-aw/python\nmkdir -p /tmp/gh-aw/python/data\nmkdir -p /tmp/gh-aw/python/charts\nmkdir -p /tmp/gh-aw/python/artifacts\n\necho \"Python environment setup complete\"\necho \"Working directory: /tmp/gh-aw/python\"\necho \"Data directory: /tmp/gh-aw/python/data\"\necho \"Charts directory: /tmp/gh-aw/python/charts\"\necho \"Artifacts directory: /tmp/gh-aw/python/artifacts\"\n" - env: UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python - name: Setup Python environment - run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/python/{data,charts,artifacts}\n# The agent sandbox cannot run the runner's CPython (glibc mismatch) and only ships\n# PyPy, which has no wheels for the chart libraries — installing them from inside the\n# sandbox builds NumPy/SciPy from source and exhausts the runner disk. Install a\n# portable uv-managed CPython plus the chart libraries under /tmp/gh-aw, which is\n# mounted read-write into the sandbox, so the agent can import them directly.\n# This must match shared/python-dataviz.md and shared/python-nlp.md so either import can\n# create the shared environment first; never recreate it, or a sibling import's packages\n# (for example the NLP libraries) would be discarded.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\nuv pip install --quiet --python /tmp/gh-aw/python/venv/bin/python numpy pandas matplotlib seaborn scipy\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/python -c \"import numpy,pandas,matplotlib,seaborn,scipy;print('chart-libraries-ready')\"\n" + name: Install Python scientific libraries + run: "# Create a virtual environment for proper package isolation (avoids --break-system-packages)\n# Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/)\n# Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC).\n# This must match shared/python-nlp.md so either import can create the shared environment first.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/pip install --quiet numpy pandas matplotlib seaborn scipy\n\n# Verify installations\n/tmp/gh-aw/python/venv/bin/python3 -c \"import numpy; print(f'NumPy {numpy.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import pandas; print(f'Pandas {pandas.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import matplotlib; print(f'Matplotlib {matplotlib.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import seaborn; print(f'Seaborn {seaborn.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import scipy; print(f'SciPy {scipy.__version__} installed')\"\n\necho \"All scientific libraries installed successfully\"\n" - if: always() name: Upload source files and data uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: if-no-files-found: warn - name: trending-source-and-data + name: python-source-and-data path: | /tmp/gh-aw/python/*.py /tmp/gh-aw/python/data/* diff --git a/.github/workflows/daily-security-red-team.lock.yml b/.github/workflows/daily-security-red-team.lock.yml index 75d1fc0498f..b1b51f31676 100644 --- a/.github/workflows/daily-security-red-team.lock.yml +++ b/.github/workflows/daily-security-red-team.lock.yml @@ -29,9 +29,9 @@ # Imports: # - shared/opencode.md # - shared/security-analysis-base.md +# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-spdd-spec-planner.lock.yml b/.github/workflows/daily-spdd-spec-planner.lock.yml index 886065e7fb0..e02b6dad301 100644 --- a/.github/workflows/daily-spdd-spec-planner.lock.yml +++ b/.github/workflows/daily-spdd-spec-planner.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md +# - shared/otlp.md # # Secrets used: # - GH_AW_AGENT_TOKEN diff --git a/.github/workflows/daily-team-evolution-insights.lock.yml b/.github/workflows/daily-team-evolution-insights.lock.yml index 3bf7ec3f8c6..04806f0977d 100644 --- a/.github/workflows/daily-team-evolution-insights.lock.yml +++ b/.github/workflows/daily-team-evolution-insights.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/goose.md +# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-testify-uber-super-expert.lock.yml b/.github/workflows/daily-testify-uber-super-expert.lock.yml index 238797097cf..1af4f2d3679 100644 --- a/.github/workflows/daily-testify-uber-super-expert.lock.yml +++ b/.github/workflows/daily-testify-uber-super-expert.lock.yml @@ -28,14 +28,14 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md -# - shared/safe-output-app.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md +# - shared/safe-output-app.md +# - shared/otlp.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/daily-token-consumption-report.lock.yml b/.github/workflows/daily-token-consumption-report.lock.yml index 1dfb84324ff..1b93fc97525 100644 --- a/.github/workflows/daily-token-consumption-report.lock.yml +++ b/.github/workflows/daily-token-consumption-report.lock.yml @@ -30,9 +30,9 @@ # - shared/goose.md # - shared/mcp/sentry.md # - shared/mcp/grafana.md +# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/dead-code-remover.lock.yml b/.github/workflows/dead-code-remover.lock.yml index 1bfcbbbe0af..6ada4394113 100644 --- a/.github/workflows/dead-code-remover.lock.yml +++ b/.github/workflows/dead-code-remover.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md +# - shared/otlp.md # # Secrets used: # - GH_AW_CI_TRIGGER_TOKEN diff --git a/.github/workflows/delight.lock.yml b/.github/workflows/delight.lock.yml index a77a7c37639..f0f58b43bb6 100644 --- a/.github/workflows/delight.lock.yml +++ b/.github/workflows/delight.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md +# - shared/daily-audit-discussion.md # - shared/repo-memory-standard.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/dependabot-burner.lock.yml b/.github/workflows/dependabot-burner.lock.yml index bb2475fbd10..6b28bc32b5a 100644 --- a/.github/workflows/dependabot-burner.lock.yml +++ b/.github/workflows/dependabot-burner.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/mcp-pagination.md +# - shared/activation-app.md # - shared/otlp.md # - shared/reporting.md -# - shared/activation-app.md # - shared/daily-pr-base.md # # Secrets used: diff --git a/.github/workflows/detection-analysis-report.lock.yml b/.github/workflows/detection-analysis-report.lock.yml index 8a05673c5fb..7265204fb92 100644 --- a/.github/workflows/detection-analysis-report.lock.yml +++ b/.github/workflows/detection-analysis-report.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/aw-logs-24h-fetch-setup.md -# - shared/reporting.md # - shared/trending-charts-simple.md # - shared/daily-audit-discussion.md # - shared/otlp.md +# - shared/aw-logs-24h-fetch-setup.md +# - shared/reporting.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # @@ -561,10 +561,6 @@ jobs: with: key: agentic-logs path: .github/aw/logs - - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Download logs from last 24 hours - run: ./gh-aw logs --start-date -1d --count 3000 -o /tmp/gh-aw/aw-mcp/logs - env: UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python name: Setup Python environment @@ -579,6 +575,10 @@ jobs: /tmp/gh-aw/python/*.py /tmp/gh-aw/python/data/* retention-days: 30 + - env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + name: Download logs from last 24 hours + run: ./gh-aw logs --start-date -1d --count 3000 -o /tmp/gh-aw/aw-mcp/logs - name: Configure Git credentials env: diff --git a/.github/workflows/developer-docs-consolidator.lock.yml b/.github/workflows/developer-docs-consolidator.lock.yml index d822e9a4208..ecf06e0d4df 100644 --- a/.github/workflows/developer-docs-consolidator.lock.yml +++ b/.github/workflows/developer-docs-consolidator.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/docs-noob-tester.lock.yml b/.github/workflows/docs-noob-tester.lock.yml index 9b36fd03f53..d4b45c5f3b3 100644 --- a/.github/workflows/docs-noob-tester.lock.yml +++ b/.github/workflows/docs-noob-tester.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - shared/docs-server-lifecycle.md # - shared/keep-it-short.md # - shared/otlp.md -# - shared/daily-audit-discussion.md -# - shared/reporting.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/duplicate-code-detector.lock.yml b/.github/workflows/duplicate-code-detector.lock.yml index 7ffdfeb44f9..1dd91994649 100644 --- a/.github/workflows/duplicate-code-detector.lock.yml +++ b/.github/workflows/duplicate-code-detector.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/reporting.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/reporting.md # - shared/go-source-analysis.md # # Secrets used: diff --git a/.github/workflows/eslint-refiner.lock.yml b/.github/workflows/eslint-refiner.lock.yml index 6d4426e3c12..f2d9a2e18bb 100644 --- a/.github/workflows/eslint-refiner.lock.yml +++ b/.github/workflows/eslint-refiner.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md # - shared/otlp.md # - shared/reporting.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/example-workflow-analyzer.lock.yml b/.github/workflows/example-workflow-analyzer.lock.yml index e9f542eb292..a00b8d8dd5c 100644 --- a/.github/workflows/example-workflow-analyzer.lock.yml +++ b/.github/workflows/example-workflow-analyzer.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/meta-analysis-base.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/github-mcp-structural-analysis.lock.yml b/.github/workflows/github-mcp-structural-analysis.lock.yml index 8315b867abc..e3886135f73 100644 --- a/.github/workflows/github-mcp-structural-analysis.lock.yml +++ b/.github/workflows/github-mcp-structural-analysis.lock.yml @@ -29,10 +29,10 @@ # Imports: # - shared/mcp-pagination.md # - shared/github-mcp-pagination-wrappers.md -# - shared/python-dataviz.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/python-dataviz.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/github-mcp-tools-report.lock.yml b/.github/workflows/github-mcp-tools-report.lock.yml index 07092fd077a..c69516ecd1a 100644 --- a/.github/workflows/github-mcp-tools-report.lock.yml +++ b/.github/workflows/github-mcp-tools-report.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/github-remote-mcp-auth-test.lock.yml b/.github/workflows/github-remote-mcp-auth-test.lock.yml index 13e42c38cd9..7903913f832 100644 --- a/.github/workflows/github-remote-mcp-auth-test.lock.yml +++ b/.github/workflows/github-remote-mcp-auth-test.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/glossary-maintainer.lock.yml b/.github/workflows/glossary-maintainer.lock.yml index db9326dd977..ee479405499 100644 --- a/.github/workflows/glossary-maintainer.lock.yml +++ b/.github/workflows/glossary-maintainer.lock.yml @@ -30,10 +30,10 @@ # - ../skills/documentation/SKILL.md # - ../agents/technical-doc-writer.agent.md # - shared/ai-coding-dictionary.md -# - shared/otlp.md -# - shared/reporting.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/reporting.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/go-fan.lock.yml b/.github/workflows/go-fan.lock.yml index 743d1eb4f1d..e2f7f832b8c 100644 --- a/.github/workflows/go-fan.lock.yml +++ b/.github/workflows/go-fan.lock.yml @@ -27,13 +27,13 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md +# - shared/otlp.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/grumpy-reviewer.lock.yml b/.github/workflows/grumpy-reviewer.lock.yml index b3da46a1ce7..b19f3489aeb 100644 --- a/.github/workflows/grumpy-reviewer.lock.yml +++ b/.github/workflows/grumpy-reviewer.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/otlp.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/impeccable-skills-reviewer.lock.yml b/.github/workflows/impeccable-skills-reviewer.lock.yml index 1488bbe9843..3d2e68ae6a5 100644 --- a/.github/workflows/impeccable-skills-reviewer.lock.yml +++ b/.github/workflows/impeccable-skills-reviewer.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/reporting.md -# - shared/otlp.md -# - shared/pr-diff-data-fetch.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/reporting.md +# - shared/otlp.md +# - shared/pr-diff-data-fetch.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/linter-miner.lock.yml b/.github/workflows/linter-miner.lock.yml index 649a2f444c7..aaffd8453cf 100644 --- a/.github/workflows/linter-miner.lock.yml +++ b/.github/workflows/linter-miner.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/reporting.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/reporting.md # # Secrets used: # - DOCKER_PAT diff --git a/.github/workflows/lockfile-stats.lock.yml b/.github/workflows/lockfile-stats.lock.yml index 206aba3b605..1e127515bf3 100644 --- a/.github/workflows/lockfile-stats.lock.yml +++ b/.github/workflows/lockfile-stats.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/mattpocock-skills-reviewer.lock.yml b/.github/workflows/mattpocock-skills-reviewer.lock.yml index 1533e9e01c3..9a1dc908393 100644 --- a/.github/workflows/mattpocock-skills-reviewer.lock.yml +++ b/.github/workflows/mattpocock-skills-reviewer.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/pr-diff-data-fetch.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/otlp.md +# - shared/pr-diff-data-fetch.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/mcp-inspector.lock.yml b/.github/workflows/mcp-inspector.lock.yml index 814a3ae9d19..9505ddfddb9 100644 --- a/.github/workflows/mcp-inspector.lock.yml +++ b/.github/workflows/mcp-inspector.lock.yml @@ -27,6 +27,8 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - shared/mcp/ast-grep.md # - shared/mcp/datadog.md # - shared/mcp/deepwiki.md @@ -34,12 +36,10 @@ # - shared/mcp/sentry.md # - shared/mcp/slack.md # - shared/mcp/tavily.md -# - shared/otlp.md -# - shared/daily-audit-discussion.md -# - shared/reporting.md -# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/ponytail-reviewer.lock.yml b/.github/workflows/ponytail-reviewer.lock.yml index 1083e1be057..c682e7c399d 100644 --- a/.github/workflows/ponytail-reviewer.lock.yml +++ b/.github/workflows/ponytail-reviewer.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/pr-diff-data-fetch.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/otlp.md +# - shared/pr-diff-data-fetch.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/portfolio-analyst.lock.yml b/.github/workflows/portfolio-analyst.lock.yml index 376598e751d..cdf49cc2069 100644 --- a/.github/workflows/portfolio-analyst.lock.yml +++ b/.github/workflows/portfolio-analyst.lock.yml @@ -29,9 +29,9 @@ # Imports: # - shared/mcp/sentry.md # - shared/mcp/grafana.md -# - shared/reporting.md # - shared/python-dataviz.md # - shared/trends.md +# - shared/reporting.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/pr-code-quality-reviewer.lock.yml b/.github/workflows/pr-code-quality-reviewer.lock.yml index 735c67759e7..b8eb8eb118e 100644 --- a/.github/workflows/pr-code-quality-reviewer.lock.yml +++ b/.github/workflows/pr-code-quality-reviewer.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/pr-diff-data-fetch.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/otlp.md +# - shared/pr-diff-data-fetch.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/pr-nitpick-reviewer.lock.yml b/.github/workflows/pr-nitpick-reviewer.lock.yml index c494b019cfc..2d7a564fba9 100644 --- a/.github/workflows/pr-nitpick-reviewer.lock.yml +++ b/.github/workflows/pr-nitpick-reviewer.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/reporting.md -# - shared/otlp.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/reporting.md +# - shared/otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/pr-triage-agent.lock.yml b/.github/workflows/pr-triage-agent.lock.yml index 7db7fc7381f..21c1c313d2c 100644 --- a/.github/workflows/pr-triage-agent.lock.yml +++ b/.github/workflows/pr-triage-agent.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md -# - shared/otlp.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/prompt-clustering-analysis.lock.yml b/.github/workflows/prompt-clustering-analysis.lock.yml index 9d0883e8f7c..d6a243d1331 100644 --- a/.github/workflows/prompt-clustering-analysis.lock.yml +++ b/.github/workflows/prompt-clustering-analysis.lock.yml @@ -28,13 +28,13 @@ # Resolved workflow manifest: # Imports: # - shared/meta-analysis-base.md +# - shared/trending-charts-simple.md +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - ../skills/jqschema/SKILL.md # - shared/copilot-pr-data-fetch.md # - shared/python-nlp.md # - shared/otlp.md -# - shared/trending-charts-simple.md -# - shared/daily-audit-discussion.md -# - shared/reporting.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # @@ -570,18 +570,6 @@ jobs: with: key: agentic-logs path: .github/aw/logs - - name: Install gh CLI - run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_gh_cli.sh" - - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Fetch Copilot PR data - run: "# Create output directories\nmkdir -p /tmp/gh-aw/agent/pr-data\nmkdir -p /tmp/gh-aw/cache-memory\n\n# Cache files use stable names so restored caches from previous runs are reusable\n# regardless of the date they were written on. Freshness is decided by file age.\nCACHE_DIR=\"/tmp/gh-aw/cache-memory\"\nCACHE_FILE=\"$CACHE_DIR/copilot-prs-latest.json\"\nCACHE_SCHEMA_FILE=\"$CACHE_DIR/copilot-prs-latest-schema.json\"\nCACHE_MAX_AGE_SECONDS=\"${CACHE_MAX_AGE_SECONDS:-21600}\"\n\n# Returns success when the file exists, is non-empty and younger than the max age.\ncache_is_fresh() {\n cache_path=\"$1\"\n [ -s \"$cache_path\" ] || return 1\n cache_mtime=$(date -r \"$cache_path\" '+%s' 2>/dev/null) || return 1\n [ -n \"$cache_mtime\" ] || return 1\n now=$(date '+%s')\n [ \"$((now - cache_mtime))\" -lt \"$CACHE_MAX_AGE_SECONDS\" ]\n}\n\n# Check if restored cache data is still fresh enough to reuse\nif cache_is_fresh \"$CACHE_FILE\"; then\n CACHE_AGE_MINUTES=$(( ( $(date '+%s') - $(date -r \"$CACHE_FILE\" '+%s') ) / 60 ))\n echo \"✓ Found cached PR data (${CACHE_AGE_MINUTES} minutes old)\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n \n # Regenerate schema if missing\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n \n echo \"Using cached data written ${CACHE_AGE_MINUTES} minutes ago\"\n echo \"Total PRs in cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nelse\n echo \"⬇ Downloading fresh PR data...\"\n \n # Calculate date 30 days ago\n DATE_30_DAYS_AGO=$(date -d '30 days ago' '+%Y-%m-%d' 2>/dev/null || date -v-30d '+%Y-%m-%d')\n\n # Search for PRs from copilot/* branches in the last 30 days using gh CLI\n # Using branch prefix search (head:copilot/) instead of author for reliability\n echo \"Fetching Copilot PRs from the last 30 days...\"\n FETCH_TMP=\"${RUNNER_TEMP:-/tmp}/copilot-prs-fetch.json\"\n rm -f \"$FETCH_TMP\"\n FETCH_OK=true\n gh pr list --repo \"$GITHUB_REPOSITORY\" \\\n --search \"head:copilot/ created:>=${DATE_30_DAYS_AGO}\" \\\n --state all \\\n --json number,title,author,headRefName,createdAt,state,url,body,labels,updatedAt,closedAt,mergedAt \\\n --limit 1000 \\\n > \"$FETCH_TMP\" || FETCH_OK=false\n\n if [ \"$FETCH_OK\" != \"true\" ] || ! jq -e 'type == \"array\"' \"$FETCH_TMP\" >/dev/null 2>&1; then\n # Transient GitHub API failures (e.g. 503) must not fail the whole run when\n # stale cached data is still available; fall back to it instead.\n if [ -s \"$CACHE_FILE\" ]; then\n echo \"::warning::Failed to fetch Copilot PR data; falling back to stale cached data\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n echo \"Total PRs in stale cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\n echo \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\n echo \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n exit 0\n fi\n echo \"::error::Failed to fetch Copilot PR data and no cached data is available\"\n exit 1\n fi\n\n cp \"$FETCH_TMP\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n rm -f \"$FETCH_TMP\"\n\n # Generate schema for reference\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n\n # Store in cache under stable names so future runs can reuse it on any date\n cp /tmp/gh-aw/agent/pr-data/copilot-prs.json \"$CACHE_FILE\"\n cp /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json \"$CACHE_SCHEMA_FILE\"\n\n # Drop legacy date-keyed cache entries so the cache does not grow unbounded\n rm -f \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9].json \\\n \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]-schema.json 2>/dev/null || true\n\n echo \"✓ PR data saved to cache: $(basename \"$CACHE_FILE\")\"\n echo \"Total PRs found: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nfi\n\n# Always ensure data is available at expected locations for backward compatibility\necho \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\necho \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n" - - env: - UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python - name: Setup Python NLP environment - run: "mkdir -p /tmp/gh-aw/python/{data,charts,artifacts}\n# Create a virtual environment for proper package isolation (avoids --break-system-packages)\n# Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/)\n# Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC).\n# This must match shared/python-dataviz.md so either import can create the shared environment first.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/pip install --quiet nltk scikit-learn textblob wordcloud\n\n# Download required NLTK corpora\n/tmp/gh-aw/python/venv/bin/python3 -c \"\nimport nltk\nfor corpus in ['punkt_tab', 'stopwords', 'vader_lexicon', 'averaged_perceptron_tagger_eng']:\n nltk.download(corpus, quiet=True)\nprint('NLTK corpora ready')\n\"\n\n/tmp/gh-aw/python/venv/bin/python3 -c \"import sklearn; print(f'scikit-learn {sklearn.__version__}')\"\n" - env: UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python name: Setup Python environment @@ -596,6 +584,18 @@ jobs: /tmp/gh-aw/python/*.py /tmp/gh-aw/python/data/* retention-days: 30 + - name: Install gh CLI + run: | + bash "${RUNNER_TEMP}/gh-aw/actions/install_gh_cli.sh" + - env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + name: Fetch Copilot PR data + run: "# Create output directories\nmkdir -p /tmp/gh-aw/agent/pr-data\nmkdir -p /tmp/gh-aw/cache-memory\n\n# Cache files use stable names so restored caches from previous runs are reusable\n# regardless of the date they were written on. Freshness is decided by file age.\nCACHE_DIR=\"/tmp/gh-aw/cache-memory\"\nCACHE_FILE=\"$CACHE_DIR/copilot-prs-latest.json\"\nCACHE_SCHEMA_FILE=\"$CACHE_DIR/copilot-prs-latest-schema.json\"\nCACHE_MAX_AGE_SECONDS=\"${CACHE_MAX_AGE_SECONDS:-21600}\"\n\n# Returns success when the file exists, is non-empty and younger than the max age.\ncache_is_fresh() {\n cache_path=\"$1\"\n [ -s \"$cache_path\" ] || return 1\n cache_mtime=$(date -r \"$cache_path\" '+%s' 2>/dev/null) || return 1\n [ -n \"$cache_mtime\" ] || return 1\n now=$(date '+%s')\n [ \"$((now - cache_mtime))\" -lt \"$CACHE_MAX_AGE_SECONDS\" ]\n}\n\n# Check if restored cache data is still fresh enough to reuse\nif cache_is_fresh \"$CACHE_FILE\"; then\n CACHE_AGE_MINUTES=$(( ( $(date '+%s') - $(date -r \"$CACHE_FILE\" '+%s') ) / 60 ))\n echo \"✓ Found cached PR data (${CACHE_AGE_MINUTES} minutes old)\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n \n # Regenerate schema if missing\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n \n echo \"Using cached data written ${CACHE_AGE_MINUTES} minutes ago\"\n echo \"Total PRs in cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nelse\n echo \"⬇ Downloading fresh PR data...\"\n \n # Calculate date 30 days ago\n DATE_30_DAYS_AGO=$(date -d '30 days ago' '+%Y-%m-%d' 2>/dev/null || date -v-30d '+%Y-%m-%d')\n\n # Search for PRs from copilot/* branches in the last 30 days using gh CLI\n # Using branch prefix search (head:copilot/) instead of author for reliability\n echo \"Fetching Copilot PRs from the last 30 days...\"\n FETCH_TMP=\"${RUNNER_TEMP:-/tmp}/copilot-prs-fetch.json\"\n rm -f \"$FETCH_TMP\"\n FETCH_OK=true\n gh pr list --repo \"$GITHUB_REPOSITORY\" \\\n --search \"head:copilot/ created:>=${DATE_30_DAYS_AGO}\" \\\n --state all \\\n --json number,title,author,headRefName,createdAt,state,url,body,labels,updatedAt,closedAt,mergedAt \\\n --limit 1000 \\\n > \"$FETCH_TMP\" || FETCH_OK=false\n\n if [ \"$FETCH_OK\" != \"true\" ] || ! jq -e 'type == \"array\"' \"$FETCH_TMP\" >/dev/null 2>&1; then\n # Transient GitHub API failures (e.g. 503) must not fail the whole run when\n # stale cached data is still available; fall back to it instead.\n if [ -s \"$CACHE_FILE\" ]; then\n echo \"::warning::Failed to fetch Copilot PR data; falling back to stale cached data\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n echo \"Total PRs in stale cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\n echo \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\n echo \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n exit 0\n fi\n echo \"::error::Failed to fetch Copilot PR data and no cached data is available\"\n exit 1\n fi\n\n cp \"$FETCH_TMP\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n rm -f \"$FETCH_TMP\"\n\n # Generate schema for reference\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n\n # Store in cache under stable names so future runs can reuse it on any date\n cp /tmp/gh-aw/agent/pr-data/copilot-prs.json \"$CACHE_FILE\"\n cp /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json \"$CACHE_SCHEMA_FILE\"\n\n # Drop legacy date-keyed cache entries so the cache does not grow unbounded\n rm -f \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9].json \\\n \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]-schema.json 2>/dev/null || true\n\n echo \"✓ PR data saved to cache: $(basename \"$CACHE_FILE\")\"\n echo \"Total PRs found: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nfi\n\n# Always ensure data is available at expected locations for backward compatibility\necho \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\necho \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n" + - env: + UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python + name: Setup Python NLP environment + run: "mkdir -p /tmp/gh-aw/python/{data,charts,artifacts}\n# Create a virtual environment for proper package isolation (avoids --break-system-packages)\n# Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/)\n# Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC).\n# This must match shared/python-dataviz.md so either import can create the shared environment first.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/pip install --quiet nltk scikit-learn textblob wordcloud\n\n# Download required NLTK corpora\n/tmp/gh-aw/python/venv/bin/python3 -c \"\nimport nltk\nfor corpus in ['punkt_tab', 'stopwords', 'vader_lexicon', 'averaged_perceptron_tagger_eng']:\n nltk.download(corpus, quiet=True)\nprint('NLTK corpora ready')\n\"\n\n/tmp/gh-aw/python/venv/bin/python3 -c \"import sklearn; print(f'scikit-learn {sklearn.__version__}')\"\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/purelock.lock.yml b/.github/workflows/purelock.lock.yml index bb1aae591b3..9d77514ce15 100644 --- a/.github/workflows/purelock.lock.yml +++ b/.github/workflows/purelock.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/reporting.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/reporting.md # # Secrets used: # - GH_AW_CI_TRIGGER_TOKEN diff --git a/.github/workflows/python-data-charts.lock.yml b/.github/workflows/python-data-charts.lock.yml index 20bf0513fe7..556cc4335b7 100644 --- a/.github/workflows/python-data-charts.lock.yml +++ b/.github/workflows/python-data-charts.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/reporting.md # - shared/python-dataviz.md # - shared/trends.md # - shared/charts-with-trending.md +# - shared/otlp.md +# - shared/reporting.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/refactoring-cadence.lock.yml b/.github/workflows/refactoring-cadence.lock.yml index c49a4868593..703667aa9b3 100644 --- a/.github/workflows/refactoring-cadence.lock.yml +++ b/.github/workflows/refactoring-cadence.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md +# - shared/otlp.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/refiner.lock.yml b/.github/workflows/refiner.lock.yml index d6580f86894..5dc86fdaaed 100644 --- a/.github/workflows/refiner.lock.yml +++ b/.github/workflows/refiner.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/reporting.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/otlp.md +# - shared/reporting.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/repo-audit-analyzer.lock.yml b/.github/workflows/repo-audit-analyzer.lock.yml index a913b4b590a..56612705314 100644 --- a/.github/workflows/repo-audit-analyzer.lock.yml +++ b/.github/workflows/repo-audit-analyzer.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/mcp-pagination.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/repository-quality-improver.lock.yml b/.github/workflows/repository-quality-improver.lock.yml index 3ec43cddf5d..227954012cc 100644 --- a/.github/workflows/repository-quality-improver.lock.yml +++ b/.github/workflows/repository-quality-improver.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/repository-quality-report-template.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/repository-quality-report-template.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/safe-output-health.lock.yml b/.github/workflows/safe-output-health.lock.yml index 793a31a7b03..133de8331af 100644 --- a/.github/workflows/safe-output-health.lock.yml +++ b/.github/workflows/safe-output-health.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - shared/aw-logs-24h-fetch.md # - ../skills/jqschema/SKILL.md # - shared/otlp.md -# - shared/daily-audit-discussion.md -# - shared/reporting.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/schema-consistency-checker.lock.yml b/.github/workflows/schema-consistency-checker.lock.yml index b4e34873906..0e3c67baf5b 100644 --- a/.github/workflows/schema-consistency-checker.lock.yml +++ b/.github/workflows/schema-consistency-checker.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/security-review.lock.yml b/.github/workflows/security-review.lock.yml index d20f40c20a2..3dae057dfaf 100644 --- a/.github/workflows/security-review.lock.yml +++ b/.github/workflows/security-review.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/security-analysis-base.md -# - shared/otlp.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/security-analysis-base.md +# - shared/otlp.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/semantic-function-refactor.lock.yml b/.github/workflows/semantic-function-refactor.lock.yml index 7b6818fc569..90b9db61784 100644 --- a/.github/workflows/semantic-function-refactor.lock.yml +++ b/.github/workflows/semantic-function-refactor.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/reporting.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/reporting.md # - shared/go-source-analysis.md # # Secrets used: diff --git a/.github/workflows/sergo.lock.yml b/.github/workflows/sergo.lock.yml index 695d92ef510..6eef2f85eda 100644 --- a/.github/workflows/sergo.lock.yml +++ b/.github/workflows/sergo.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/reporting.md # - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/reporting.md +# - shared/daily-audit-base.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/skillet.lock.yml b/.github/workflows/skillet.lock.yml index 77193acf794..a1236419903 100644 --- a/.github/workflows/skillet.lock.yml +++ b/.github/workflows/skillet.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/otlp.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/slide-deck-maintainer.lock.yml b/.github/workflows/slide-deck-maintainer.lock.yml index 216389d950f..3ed5cc53696 100644 --- a/.github/workflows/slide-deck-maintainer.lock.yml +++ b/.github/workflows/slide-deck-maintainer.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md +# - shared/otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-codex.lock.yml b/.github/workflows/smoke-codex.lock.yml index 6b38265413f..bde14020b22 100644 --- a/.github/workflows/smoke-codex.lock.yml +++ b/.github/workflows/smoke-codex.lock.yml @@ -28,15 +28,15 @@ # Resolved workflow manifest: # Imports: # - shared/gh.md +# - shared/reporting.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # - shared/trufflehog.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md # - shared/playwright-title-test.md -# - shared/reporting.md -# - shared/reporting-otlp.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/smoke-copilot-aoai-apikey.lock.yml b/.github/workflows/smoke-copilot-aoai-apikey.lock.yml index f27a3cea2f1..39e19bb8c23 100644 --- a/.github/workflows/smoke-copilot-aoai-apikey.lock.yml +++ b/.github/workflows/smoke-copilot-aoai-apikey.lock.yml @@ -31,11 +31,11 @@ # - shared/gh.md # - shared/reporting.md # - shared/github-queries-mcp-script.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # - shared/otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-copilot-aoai-entra.lock.yml b/.github/workflows/smoke-copilot-aoai-entra.lock.yml index ea6097f1793..e4ecc26890d 100644 --- a/.github/workflows/smoke-copilot-aoai-entra.lock.yml +++ b/.github/workflows/smoke-copilot-aoai-entra.lock.yml @@ -31,12 +31,12 @@ # - shared/gh.md # - shared/reporting.md # - shared/github-queries-mcp-script.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # - shared/otlp.md # - shared/token-telemetry-check.md # - shared/azure-auth.md # - shared/smoke-test-brevity.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # # Frontmatter env variables: # - AZURE_CONFIG_DIR: shared/azure-auth.md @@ -810,11 +810,6 @@ jobs: env: GH_AW_SKILL_DIR: ".github/skills" run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_skills.sh" - - env: - GH_AW_AZURE_CLIENT_ID: adb907fd-188c-4029-b67f-2559d96b2f1b - GH_AW_AZURE_TENANT_ID: 398a6654-997b-47e9-b12b-9515b896b4de - name: Re-authenticate Azure CLI with OIDC - run: "if [ -z \"$GH_AW_AZURE_OIDC_TOKEN_FILE\" ] || [ ! -f \"$GH_AW_AZURE_OIDC_TOKEN_FILE\" ]; then\n echo \"::error::Azure OIDC token file not found — the Fetch Azure OIDC token step may have failed\"\n exit 1\nfi\nmkdir -p \"$AZURE_CONFIG_DIR\"\nchmod 700 \"$AZURE_CONFIG_DIR\"\ncleanup() {\n rm -f \"$GH_AW_AZURE_OIDC_TOKEN_FILE\"\n}\ntrap cleanup EXIT\naz login --service-principal \\\n --username \"$GH_AW_AZURE_CLIENT_ID\" \\\n --tenant \"$GH_AW_AZURE_TENANT_ID\" \\\n --federated-token \"$(cat \"$GH_AW_AZURE_OIDC_TOKEN_FILE\")\" \\\n --output none \\\n --only-show-errors\naz account show --output table\n" - name: Setup Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: @@ -822,6 +817,11 @@ jobs: go-version-file: go.mod - name: Verify Go installation run: go version + - env: + GH_AW_AZURE_CLIENT_ID: adb907fd-188c-4029-b67f-2559d96b2f1b + GH_AW_AZURE_TENANT_ID: 398a6654-997b-47e9-b12b-9515b896b4de + name: Re-authenticate Azure CLI with OIDC + run: "if [ -z \"$GH_AW_AZURE_OIDC_TOKEN_FILE\" ] || [ ! -f \"$GH_AW_AZURE_OIDC_TOKEN_FILE\" ]; then\n echo \"::error::Azure OIDC token file not found — the Fetch Azure OIDC token step may have failed\"\n exit 1\nfi\nmkdir -p \"$AZURE_CONFIG_DIR\"\nchmod 700 \"$AZURE_CONFIG_DIR\"\ncleanup() {\n rm -f \"$GH_AW_AZURE_OIDC_TOKEN_FILE\"\n}\ntrap cleanup EXIT\naz login --service-principal \\\n --username \"$GH_AW_AZURE_CLIENT_ID\" \\\n --tenant \"$GH_AW_AZURE_TENANT_ID\" \\\n --federated-token \"$(cat \"$GH_AW_AZURE_OIDC_TOKEN_FILE\")\" \\\n --output none \\\n --only-show-errors\naz account show --output table\n" - name: Download container images run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.28.12@sha256:390051be4ed1847f774fd8980b61d3a3523574c0175d00c3fc7cdf2002a88202 ghcr.io/github/gh-aw-firewall/api-proxy:0.28.12@sha256:d7d533d87c80d87ff91ac0e21e9299055c3beedff1536262b97ed700fb065a32 ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.12@sha256:5250629d48eaedfedf2e948785228e8da29eec2a83cbab58ea0751c14a7b021d ghcr.io/github/gh-aw-firewall/squid:0.28.12@sha256:52c34aca98d2a6833c329f1505912a6949c4fda16618c010c979bd59ea99254f ghcr.io/github/gh-aw-mcpg:v0.4.14@sha256:b2f0c2b2f17b5fbe809e5bb99dc185b6ddd70df25295dc63a6d526350334eff5 ghcr.io/github/gh-aw-node@sha256:bac2192f6374d6262116399b34fc5e143d576f82719e90a18261cae7480f4d4e ghcr.io/github/github-mcp-server:v1.11.0@sha256:fbec75de11c255213fa08d80fb166abe73d851fff631c51c0079872967720699 ghcr.io/oraios/serena:1.7.0@sha256:6c9459e4246a39c9deaa4f23fb05a526ac6e237b24c8e84a927a098fa1ab6730 diff --git a/.github/workflows/smoke-copilot-arm.lock.yml b/.github/workflows/smoke-copilot-arm.lock.yml index 1cde1a577b4..d366980324f 100644 --- a/.github/workflows/smoke-copilot-arm.lock.yml +++ b/.github/workflows/smoke-copilot-arm.lock.yml @@ -28,14 +28,14 @@ # Resolved workflow manifest: # Imports: # - shared/gh.md +# - shared/reporting.md # - shared/github-queries-mcp-script.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md -# - shared/reporting.md -# - shared/reporting-otlp.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-copilot.lock.yml b/.github/workflows/smoke-copilot.lock.yml index ca71862b1cc..420a6cbdd7b 100644 --- a/.github/workflows/smoke-copilot.lock.yml +++ b/.github/workflows/smoke-copilot.lock.yml @@ -31,12 +31,12 @@ # - shared/gh.md # - shared/reporting.md # - shared/github-queries-mcp-script.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # - shared/otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md # - shared/playwright-title-test.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-crush.lock.yml b/.github/workflows/smoke-crush.lock.yml index 9e135e5de11..ff1a520d025 100644 --- a/.github/workflows/smoke-crush.lock.yml +++ b/.github/workflows/smoke-crush.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/crush.md # - shared/gh.md +# - shared/reporting.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md -# - shared/reporting.md -# - shared/reporting-otlp.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/smoke-cursor.lock.yml b/.github/workflows/smoke-cursor.lock.yml index 76b9767f870..ea63eb27716 100644 --- a/.github/workflows/smoke-cursor.lock.yml +++ b/.github/workflows/smoke-cursor.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/cursor.md # - shared/gh.md +# - shared/reporting.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md -# - shared/reporting.md -# - shared/reporting-otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-deepseek-harness.lock.yml b/.github/workflows/smoke-deepseek-harness.lock.yml index 26e17f3e1ab..070345f7eae 100644 --- a/.github/workflows/smoke-deepseek-harness.lock.yml +++ b/.github/workflows/smoke-deepseek-harness.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/deepseek-harness.md # - shared/gh.md +# - shared/reporting.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md -# - shared/reporting.md -# - shared/reporting-otlp.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/smoke-gemini.lock.yml b/.github/workflows/smoke-gemini.lock.yml index a0cc993f2ce..15ae922ed66 100644 --- a/.github/workflows/smoke-gemini.lock.yml +++ b/.github/workflows/smoke-gemini.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: +# - shared/reporting.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md # - shared/playwright-title-test.md -# - shared/reporting.md -# - shared/reporting-otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-goose.lock.yml b/.github/workflows/smoke-goose.lock.yml index 91f72bf730f..b13a3e52361 100644 --- a/.github/workflows/smoke-goose.lock.yml +++ b/.github/workflows/smoke-goose.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/goose.md # - shared/gh.md +# - shared/reporting.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md -# - shared/reporting.md -# - shared/reporting-otlp.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/smoke-kiro.lock.yml b/.github/workflows/smoke-kiro.lock.yml index ec272c8ea77..0f6386d8ce0 100644 --- a/.github/workflows/smoke-kiro.lock.yml +++ b/.github/workflows/smoke-kiro.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/kiro.md # - shared/gh.md +# - shared/reporting.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md -# - shared/reporting.md -# - shared/reporting-otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-opencode.lock.yml b/.github/workflows/smoke-opencode.lock.yml index 10d2796fae8..8fb659493fc 100644 --- a/.github/workflows/smoke-opencode.lock.yml +++ b/.github/workflows/smoke-opencode.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/opencode.md # - shared/gh.md +# - shared/reporting.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md -# - shared/reporting.md -# - shared/reporting-otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-pi.lock.yml b/.github/workflows/smoke-pi.lock.yml index 571605b8de5..873d13f1a93 100644 --- a/.github/workflows/smoke-pi.lock.yml +++ b/.github/workflows/smoke-pi.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/gh.md -# - shared/otlp.md -# - shared/smoke-test-brevity.md # - shared/reporting.md +# - shared/otlp.md # - shared/reporting-otlp.md +# - shared/smoke-test-brevity.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/spec-extractor.lock.yml b/.github/workflows/spec-extractor.lock.yml index 01b51171e1b..38d402253bb 100644 --- a/.github/workflows/spec-extractor.lock.yml +++ b/.github/workflows/spec-extractor.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md -# - shared/otlp.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md +# - shared/otlp.md # # Secrets used: # - GH_AW_CI_TRIGGER_TOKEN diff --git a/.github/workflows/spec-librarian.lock.yml b/.github/workflows/spec-librarian.lock.yml index 1cf9a8f6ac2..26294875ffb 100644 --- a/.github/workflows/spec-librarian.lock.yml +++ b/.github/workflows/spec-librarian.lock.yml @@ -29,12 +29,12 @@ # Imports: # - shared/reporting.md # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/daily-issue-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md +# - shared/otlp.md # # Secrets used: # - GH_AW_AGENT_TOKEN diff --git a/.github/workflows/stale-repo-identifier.lock.yml b/.github/workflows/stale-repo-identifier.lock.yml index d8dc9593d8f..63a9b8ff6a8 100644 --- a/.github/workflows/stale-repo-identifier.lock.yml +++ b/.github/workflows/stale-repo-identifier.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/mcp-pagination.md # - shared/github-guard-policy.md +# - shared/trending-charts-simple.md +# - shared/daily-audit-discussion.md # - ../skills/jqschema/SKILL.md # - shared/otlp.md # - shared/reporting.md -# - shared/trending-charts-simple.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # diff --git a/.github/workflows/terminal-stylist.lock.yml b/.github/workflows/terminal-stylist.lock.yml index 26e481d7bca..9a38d8e80c1 100644 --- a/.github/workflows/terminal-stylist.lock.yml +++ b/.github/workflows/terminal-stylist.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/reporting.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/typist.lock.yml b/.github/workflows/typist.lock.yml index e9af110c3a1..c735546e844 100644 --- a/.github/workflows/typist.lock.yml +++ b/.github/workflows/typist.lock.yml @@ -28,11 +28,11 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/ubuntu-image-analyzer.lock.yml b/.github/workflows/ubuntu-image-analyzer.lock.yml index 880f97058d8..edd13d986bf 100644 --- a/.github/workflows/ubuntu-image-analyzer.lock.yml +++ b/.github/workflows/ubuntu-image-analyzer.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md +# - shared/otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/uk-ai-operational-resilience.lock.yml b/.github/workflows/uk-ai-operational-resilience.lock.yml index e8805e5461d..c3938ac911c 100644 --- a/.github/workflows/uk-ai-operational-resilience.lock.yml +++ b/.github/workflows/uk-ai-operational-resilience.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/mcp-pagination.md +# - shared/daily-audit-discussion.md # - shared/otlp.md # - shared/reporting.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/unbloat-docs.lock.yml b/.github/workflows/unbloat-docs.lock.yml index fc7a15872ca..d2650b4d792 100644 --- a/.github/workflows/unbloat-docs.lock.yml +++ b/.github/workflows/unbloat-docs.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/activation-app.md # - shared/otlp.md # - shared/reporting.md -# - shared/activation-app.md # - shared/daily-pr-base.md # # Secrets used: diff --git a/.github/workflows/weekly-issue-summary.lock.yml b/.github/workflows/weekly-issue-summary.lock.yml index aba771757ba..ffb5503e123 100644 --- a/.github/workflows/weekly-issue-summary.lock.yml +++ b/.github/workflows/weekly-issue-summary.lock.yml @@ -28,12 +28,12 @@ # Resolved workflow manifest: # Imports: # - shared/github-guard-policy.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/daily-audit-base.md # - shared/python-dataviz.md # - shared/trends.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - CODEX_API_KEY From d887f9790255f1e55f82f0fc2aaf0e39a4d4dc39 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Tue, 1 Sep 2026 21:56:48 +0000 Subject: [PATCH 9/9] Restore scoped dependency update Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com> --- .github/workflows/agent-job-health.lock.yml | 4 +- .../workflows/api-consumption-report.lock.yml | 8 +-- .github/workflows/archie.lock.yml | 2 +- .../workflows/architecture-guardian.lock.yml | 2 +- .github/workflows/audit-workflows.lock.yml | 8 +-- .github/workflows/blog-auditor.lock.yml | 2 +- .../breaking-change-checker.lock.yml | 2 +- .github/workflows/ci-coach.lock.yml | 4 +- .../claude-code-user-docs-review.lock.yml | 2 +- .github/workflows/cloclo.lock.yml | 4 +- .../workflows/code-scanning-fixer.lock.yml | 2 +- .github/workflows/code-simplifier.lock.yml | 2 +- .../workflows/copilot-agent-analysis.lock.yml | 6 +- .../copilot-pr-merged-report.lock.yml | 6 +- .../copilot-pr-nlp-analysis.lock.yml | 22 +++---- .../copilot-pr-prompt-analysis.lock.yml | 6 +- .../copilot-session-insights.lock.yml | 6 +- .../daily-architecture-diagram.lock.yml | 2 +- .../workflows/daily-cli-performance.lock.yml | 4 +- .../workflows/daily-cli-tools-tester.lock.yml | 2 +- .github/workflows/daily-code-metrics.lock.yml | 4 +- .../workflows/daily-compiler-quality.lock.yml | 4 +- ...ly-compiler-threat-spec-optimizer.lock.yml | 2 +- .github/workflows/daily-doc-healer.lock.yml | 2 +- .../daily-experiment-report.lock.yml | 2 +- .github/workflows/daily-file-diet.lock.yml | 4 +- .../daily-formal-spec-verifier.lock.yml | 2 +- .../workflows/daily-function-namer.lock.yml | 4 +- .../workflows/daily-geo-optimizer.lock.yml | 2 +- .../daily-graft-intelligence.lock.yml | 6 +- .../workflows/daily-issues-report.lock.yml | 66 +++++++++---------- .../daily-malicious-code-scan.lock.yml | 2 +- .../daily-mcp-concurrency-analysis.lock.yml | 2 +- .../daily-multi-device-docs-tester.lock.yml | 2 +- .github/workflows/daily-news.lock.yml | 6 +- .../daily-observability-report.lock.yml | 2 +- .../daily-performance-summary.lock.yml | 4 +- .github/workflows/daily-regulatory.lock.yml | 2 +- .../daily-reliability-review.lock.yml | 2 +- .../daily-rendering-scripts-verifier.lock.yml | 2 +- .../workflows/daily-repo-chronicle.lock.yml | 6 +- .../daily-safe-output-integrator.lock.yml | 2 +- .../daily-safe-output-optimizer.lock.yml | 2 +- .../daily-safe-outputs-conformance.lock.yml | 2 +- .../workflows/daily-secrets-analysis.lock.yml | 2 +- .../daily-security-observability.lock.yml | 20 +++--- .../daily-security-red-team.lock.yml | 2 +- .../daily-spdd-spec-planner.lock.yml | 2 +- .../daily-team-evolution-insights.lock.yml | 2 +- .../daily-testify-uber-super-expert.lock.yml | 4 +- .../daily-token-consumption-report.lock.yml | 2 +- .github/workflows/dead-code-remover.lock.yml | 2 +- .github/workflows/delight.lock.yml | 2 +- .github/workflows/dependabot-burner.lock.yml | 2 +- .../detection-analysis-report.lock.yml | 12 ++-- .../developer-docs-consolidator.lock.yml | 4 +- .github/workflows/docs-noob-tester.lock.yml | 4 +- .../duplicate-code-detector.lock.yml | 4 +- .github/workflows/eslint-refiner.lock.yml | 2 +- .../example-workflow-analyzer.lock.yml | 2 +- .../github-mcp-structural-analysis.lock.yml | 4 +- .../github-mcp-tools-report.lock.yml | 2 +- .../github-remote-mcp-auth-test.lock.yml | 2 +- .../workflows/glossary-maintainer.lock.yml | 4 +- .github/workflows/go-fan.lock.yml | 2 +- .github/workflows/grumpy-reviewer.lock.yml | 2 +- .../impeccable-skills-reviewer.lock.yml | 6 +- .github/workflows/linter-miner.lock.yml | 4 +- .github/workflows/lockfile-stats.lock.yml | 2 +- .../mattpocock-skills-reviewer.lock.yml | 4 +- .github/workflows/mcp-inspector.lock.yml | 8 +-- .github/workflows/ponytail-reviewer.lock.yml | 4 +- .github/workflows/portfolio-analyst.lock.yml | 2 +- .../pr-code-quality-reviewer.lock.yml | 4 +- .../workflows/pr-nitpick-reviewer.lock.yml | 4 +- .github/workflows/pr-triage-agent.lock.yml | 2 +- .../prompt-clustering-analysis.lock.yml | 30 ++++----- .github/workflows/purelock.lock.yml | 4 +- .github/workflows/python-data-charts.lock.yml | 4 +- .../workflows/refactoring-cadence.lock.yml | 2 +- .github/workflows/refiner.lock.yml | 4 +- .../workflows/repo-audit-analyzer.lock.yml | 2 +- .../repository-quality-improver.lock.yml | 4 +- .github/workflows/safe-output-health.lock.yml | 4 +- .../schema-consistency-checker.lock.yml | 2 +- .github/workflows/security-review.lock.yml | 4 +- .../semantic-function-refactor.lock.yml | 4 +- .github/workflows/sergo.lock.yml | 6 +- .github/workflows/skillet.lock.yml | 2 +- .../workflows/slide-deck-maintainer.lock.yml | 2 +- .github/workflows/smoke-codex.lock.yml | 8 +-- .../smoke-copilot-aoai-apikey.lock.yml | 4 +- .../smoke-copilot-aoai-entra.lock.yml | 14 ++-- .github/workflows/smoke-copilot-arm.lock.yml | 8 +-- .github/workflows/smoke-copilot.lock.yml | 4 +- .github/workflows/smoke-crush.lock.yml | 4 +- .github/workflows/smoke-cursor.lock.yml | 4 +- .../workflows/smoke-deepseek-harness.lock.yml | 4 +- .github/workflows/smoke-gemini.lock.yml | 4 +- .github/workflows/smoke-goose.lock.yml | 4 +- .github/workflows/smoke-kiro.lock.yml | 4 +- .github/workflows/smoke-opencode.lock.yml | 4 +- .github/workflows/smoke-pi.lock.yml | 4 +- .github/workflows/spec-extractor.lock.yml | 2 +- .github/workflows/spec-librarian.lock.yml | 2 +- .../workflows/stale-repo-identifier.lock.yml | 4 +- .github/workflows/terminal-stylist.lock.yml | 6 +- .github/workflows/typist.lock.yml | 4 +- .../workflows/ubuntu-image-analyzer.lock.yml | 2 +- .../uk-ai-operational-resilience.lock.yml | 2 +- .github/workflows/unbloat-docs.lock.yml | 2 +- .../workflows/weekly-issue-summary.lock.yml | 4 +- 112 files changed, 263 insertions(+), 263 deletions(-) diff --git a/.github/workflows/agent-job-health.lock.yml b/.github/workflows/agent-job-health.lock.yml index 3aa5b07ba6a..1d6193c8624 100644 --- a/.github/workflows/agent-job-health.lock.yml +++ b/.github/workflows/agent-job-health.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: +# - shared/aw-logs-24h-fetch.md +# - ../skills/jqschema/SKILL.md # - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md # - shared/daily-audit-base.md -# - shared/aw-logs-24h-fetch.md -# - ../skills/jqschema/SKILL.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/api-consumption-report.lock.yml b/.github/workflows/api-consumption-report.lock.yml index d473f6ad01b..84542fbd45e 100644 --- a/.github/workflows/api-consumption-report.lock.yml +++ b/.github/workflows/api-consumption-report.lock.yml @@ -28,17 +28,17 @@ # Resolved workflow manifest: # Imports: # - shared/cache-memory-trending.md -# - shared/trending-charts-simple.md -# - shared/daily-audit-discussion.md # - ../skills/jqschema/SKILL.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-base.md -# - shared/daily-audit-charts.md +# - shared/trending-charts-simple.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md # - shared/graders.md +# - shared/daily-audit-discussion.md +# - shared/daily-audit-base.md +# - shared/daily-audit-charts.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/archie.lock.yml b/.github/workflows/archie.lock.yml index 697739bb37d..aa9dd6ddad5 100644 --- a/.github/workflows/archie.lock.yml +++ b/.github/workflows/archie.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md -# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/architecture-guardian.lock.yml b/.github/workflows/architecture-guardian.lock.yml index 2cc2116a6b4..5b67cb2a06b 100644 --- a/.github/workflows/architecture-guardian.lock.yml +++ b/.github/workflows/architecture-guardian.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md +# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md -# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/audit-workflows.lock.yml b/.github/workflows/audit-workflows.lock.yml index f39051185d0..5acdb9fc04e 100644 --- a/.github/workflows/audit-workflows.lock.yml +++ b/.github/workflows/audit-workflows.lock.yml @@ -27,19 +27,19 @@ # # Resolved workflow manifest: # Imports: -# - shared/trending-charts-simple.md -# - shared/daily-audit-discussion.md # - shared/repo-memory-standard.md # - ../skills/jqschema/SKILL.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-base.md -# - shared/daily-audit-charts.md # - shared/default-ai-credits-pricing.md +# - shared/trending-charts-simple.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md # - shared/graders.md +# - shared/daily-audit-discussion.md +# - shared/daily-audit-base.md +# - shared/daily-audit-charts.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/blog-auditor.lock.yml b/.github/workflows/blog-auditor.lock.yml index c58b7f62919..851446197db 100644 --- a/.github/workflows/blog-auditor.lock.yml +++ b/.github/workflows/blog-auditor.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-base.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md diff --git a/.github/workflows/breaking-change-checker.lock.yml b/.github/workflows/breaking-change-checker.lock.yml index 621f1bf7f51..49cbe967dd8 100644 --- a/.github/workflows/breaking-change-checker.lock.yml +++ b/.github/workflows/breaking-change-checker.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md +# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md -# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/ci-coach.lock.yml b/.github/workflows/ci-coach.lock.yml index 010b188539e..b738303a0a6 100644 --- a/.github/workflows/ci-coach.lock.yml +++ b/.github/workflows/ci-coach.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - ../skills/jqschema/SKILL.md -# - shared/ci-data-analysis.md # - shared/ci-optimization-strategies.md # - shared/reporting.md # - shared/otlp.md +# - ../skills/jqschema/SKILL.md +# - shared/ci-data-analysis.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/claude-code-user-docs-review.lock.yml b/.github/workflows/claude-code-user-docs-review.lock.yml index 88bd1291338..a45b4100cfd 100644 --- a/.github/workflows/claude-code-user-docs-review.lock.yml +++ b/.github/workflows/claude-code-user-docs-review.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-base.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md diff --git a/.github/workflows/cloclo.lock.yml b/.github/workflows/cloclo.lock.yml index f04848a5049..cb5546ceb58 100644 --- a/.github/workflows/cloclo.lock.yml +++ b/.github/workflows/cloclo.lock.yml @@ -27,10 +27,10 @@ # Resolved workflow manifest: # Imports: # - ../skills/jqschema/SKILL.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # - shared/reporting.md # - shared/otlp.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/code-scanning-fixer.lock.yml b/.github/workflows/code-scanning-fixer.lock.yml index 887906c6cd5..2923ab916cf 100644 --- a/.github/workflows/code-scanning-fixer.lock.yml +++ b/.github/workflows/code-scanning-fixer.lock.yml @@ -30,10 +30,10 @@ # - shared/mcp-pagination.md # - shared/skip-if-issue-open.md # - shared/security-analysis-base.md +# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md -# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/code-simplifier.lock.yml b/.github/workflows/code-simplifier.lock.yml index 6a17975d7b1..a88dc8af2f6 100644 --- a/.github/workflows/code-simplifier.lock.yml +++ b/.github/workflows/code-simplifier.lock.yml @@ -29,10 +29,10 @@ # Imports: # - shared/mcp-pagination.md # - shared/skip-if-issue-open.md +# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md -# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/copilot-agent-analysis.lock.yml b/.github/workflows/copilot-agent-analysis.lock.yml index 4f88e6cd95a..0f447572765 100644 --- a/.github/workflows/copilot-agent-analysis.lock.yml +++ b/.github/workflows/copilot-agent-analysis.lock.yml @@ -27,13 +27,13 @@ # # Resolved workflow manifest: # Imports: +# - shared/repo-memory-standard.md +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/repo-memory-standard.md +# - shared/daily-audit-base.md # - shared/copilot-pr-data-fetch.md # - shared/copilot-pr-analysis-base.md -# - shared/otlp.md -# - shared/daily-audit-base.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/copilot-pr-merged-report.lock.yml b/.github/workflows/copilot-pr-merged-report.lock.yml index 9cada2408c0..483fb7aee8d 100644 --- a/.github/workflows/copilot-pr-merged-report.lock.yml +++ b/.github/workflows/copilot-pr-merged-report.lock.yml @@ -28,12 +28,12 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md -# - shared/daily-audit-discussion.md # - shared/gh.md -# - shared/copilot-pr-data-fetch.md -# - shared/copilot-pr-analysis-base.md # - shared/otlp.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md +# - shared/copilot-pr-data-fetch.md +# - shared/copilot-pr-analysis-base.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/copilot-pr-nlp-analysis.lock.yml b/.github/workflows/copilot-pr-nlp-analysis.lock.yml index ab3d83f3dd2..599ab2e9b3c 100644 --- a/.github/workflows/copilot-pr-nlp-analysis.lock.yml +++ b/.github/workflows/copilot-pr-nlp-analysis.lock.yml @@ -27,15 +27,15 @@ # # Resolved workflow manifest: # Imports: -# - shared/daily-audit-discussion.md # - shared/repo-memory-standard.md -# - shared/copilot-pr-data-fetch.md # - shared/python-dataviz.md # - shared/python-nlp.md # - shared/reporting.md -# - shared/copilot-pr-analysis-base.md # - shared/otlp.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md +# - shared/copilot-pr-data-fetch.md +# - shared/copilot-pr-analysis-base.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN @@ -541,14 +541,6 @@ jobs: MEMORY_DIR: /tmp/gh-aw/repo-memory/default CREATE_ORPHAN: true run: bash "${RUNNER_TEMP}/gh-aw/actions/clone_repo_memory_branch.sh" - - name: Install gh CLI - run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_gh_cli.sh" - - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Fetch Copilot PR data - run: "# Create output directories\nmkdir -p /tmp/gh-aw/agent/pr-data\nmkdir -p /tmp/gh-aw/cache-memory\n\n# Cache files use stable names so restored caches from previous runs are reusable\n# regardless of the date they were written on. Freshness is decided by file age.\nCACHE_DIR=\"/tmp/gh-aw/cache-memory\"\nCACHE_FILE=\"$CACHE_DIR/copilot-prs-latest.json\"\nCACHE_SCHEMA_FILE=\"$CACHE_DIR/copilot-prs-latest-schema.json\"\nCACHE_MAX_AGE_SECONDS=\"${CACHE_MAX_AGE_SECONDS:-21600}\"\n\n# Returns success when the file exists, is non-empty and younger than the max age.\ncache_is_fresh() {\n cache_path=\"$1\"\n [ -s \"$cache_path\" ] || return 1\n cache_mtime=$(date -r \"$cache_path\" '+%s' 2>/dev/null) || return 1\n [ -n \"$cache_mtime\" ] || return 1\n now=$(date '+%s')\n [ \"$((now - cache_mtime))\" -lt \"$CACHE_MAX_AGE_SECONDS\" ]\n}\n\n# Check if restored cache data is still fresh enough to reuse\nif cache_is_fresh \"$CACHE_FILE\"; then\n CACHE_AGE_MINUTES=$(( ( $(date '+%s') - $(date -r \"$CACHE_FILE\" '+%s') ) / 60 ))\n echo \"✓ Found cached PR data (${CACHE_AGE_MINUTES} minutes old)\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n \n # Regenerate schema if missing\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n \n echo \"Using cached data written ${CACHE_AGE_MINUTES} minutes ago\"\n echo \"Total PRs in cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nelse\n echo \"⬇ Downloading fresh PR data...\"\n \n # Calculate date 30 days ago\n DATE_30_DAYS_AGO=$(date -d '30 days ago' '+%Y-%m-%d' 2>/dev/null || date -v-30d '+%Y-%m-%d')\n\n # Search for PRs from copilot/* branches in the last 30 days using gh CLI\n # Using branch prefix search (head:copilot/) instead of author for reliability\n echo \"Fetching Copilot PRs from the last 30 days...\"\n FETCH_TMP=\"${RUNNER_TEMP:-/tmp}/copilot-prs-fetch.json\"\n rm -f \"$FETCH_TMP\"\n FETCH_OK=true\n gh pr list --repo \"$GITHUB_REPOSITORY\" \\\n --search \"head:copilot/ created:>=${DATE_30_DAYS_AGO}\" \\\n --state all \\\n --json number,title,author,headRefName,createdAt,state,url,body,labels,updatedAt,closedAt,mergedAt \\\n --limit 1000 \\\n > \"$FETCH_TMP\" || FETCH_OK=false\n\n if [ \"$FETCH_OK\" != \"true\" ] || ! jq -e 'type == \"array\"' \"$FETCH_TMP\" >/dev/null 2>&1; then\n # Transient GitHub API failures (e.g. 503) must not fail the whole run when\n # stale cached data is still available; fall back to it instead.\n if [ -s \"$CACHE_FILE\" ]; then\n echo \"::warning::Failed to fetch Copilot PR data; falling back to stale cached data\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n echo \"Total PRs in stale cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\n echo \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\n echo \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n exit 0\n fi\n echo \"::error::Failed to fetch Copilot PR data and no cached data is available\"\n exit 1\n fi\n\n cp \"$FETCH_TMP\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n rm -f \"$FETCH_TMP\"\n\n # Generate schema for reference\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n\n # Store in cache under stable names so future runs can reuse it on any date\n cp /tmp/gh-aw/agent/pr-data/copilot-prs.json \"$CACHE_FILE\"\n cp /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json \"$CACHE_SCHEMA_FILE\"\n\n # Drop legacy date-keyed cache entries so the cache does not grow unbounded\n rm -f \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9].json \\\n \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]-schema.json 2>/dev/null || true\n\n echo \"✓ PR data saved to cache: $(basename \"$CACHE_FILE\")\"\n echo \"Total PRs found: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nfi\n\n# Always ensure data is available at expected locations for backward compatibility\necho \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\necho \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n" - name: Setup Python environment run: "# Create working directory for Python scripts\nmkdir -p /tmp/gh-aw/python\nmkdir -p /tmp/gh-aw/python/data\nmkdir -p /tmp/gh-aw/python/charts\nmkdir -p /tmp/gh-aw/python/artifacts\n\necho \"Python environment setup complete\"\necho \"Working directory: /tmp/gh-aw/python\"\necho \"Data directory: /tmp/gh-aw/python/data\"\necho \"Charts directory: /tmp/gh-aw/python/charts\"\necho \"Artifacts directory: /tmp/gh-aw/python/artifacts\"\n" - env: @@ -569,6 +561,14 @@ jobs: UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python name: Setup Python NLP environment run: "mkdir -p /tmp/gh-aw/python/{data,charts,artifacts}\n# Create a virtual environment for proper package isolation (avoids --break-system-packages)\n# Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/)\n# Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC).\n# This must match shared/python-dataviz.md so either import can create the shared environment first.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/pip install --quiet nltk scikit-learn textblob wordcloud\n\n# Download required NLTK corpora\n/tmp/gh-aw/python/venv/bin/python3 -c \"\nimport nltk\nfor corpus in ['punkt_tab', 'stopwords', 'vader_lexicon', 'averaged_perceptron_tagger_eng']:\n nltk.download(corpus, quiet=True)\nprint('NLTK corpora ready')\n\"\n\n/tmp/gh-aw/python/venv/bin/python3 -c \"import sklearn; print(f'scikit-learn {sklearn.__version__}')\"\n" + - name: Install gh CLI + run: | + bash "${RUNNER_TEMP}/gh-aw/actions/install_gh_cli.sh" + - env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + name: Fetch Copilot PR data + run: "# Create output directories\nmkdir -p /tmp/gh-aw/agent/pr-data\nmkdir -p /tmp/gh-aw/cache-memory\n\n# Cache files use stable names so restored caches from previous runs are reusable\n# regardless of the date they were written on. Freshness is decided by file age.\nCACHE_DIR=\"/tmp/gh-aw/cache-memory\"\nCACHE_FILE=\"$CACHE_DIR/copilot-prs-latest.json\"\nCACHE_SCHEMA_FILE=\"$CACHE_DIR/copilot-prs-latest-schema.json\"\nCACHE_MAX_AGE_SECONDS=\"${CACHE_MAX_AGE_SECONDS:-21600}\"\n\n# Returns success when the file exists, is non-empty and younger than the max age.\ncache_is_fresh() {\n cache_path=\"$1\"\n [ -s \"$cache_path\" ] || return 1\n cache_mtime=$(date -r \"$cache_path\" '+%s' 2>/dev/null) || return 1\n [ -n \"$cache_mtime\" ] || return 1\n now=$(date '+%s')\n [ \"$((now - cache_mtime))\" -lt \"$CACHE_MAX_AGE_SECONDS\" ]\n}\n\n# Check if restored cache data is still fresh enough to reuse\nif cache_is_fresh \"$CACHE_FILE\"; then\n CACHE_AGE_MINUTES=$(( ( $(date '+%s') - $(date -r \"$CACHE_FILE\" '+%s') ) / 60 ))\n echo \"✓ Found cached PR data (${CACHE_AGE_MINUTES} minutes old)\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n \n # Regenerate schema if missing\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n \n echo \"Using cached data written ${CACHE_AGE_MINUTES} minutes ago\"\n echo \"Total PRs in cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nelse\n echo \"⬇ Downloading fresh PR data...\"\n \n # Calculate date 30 days ago\n DATE_30_DAYS_AGO=$(date -d '30 days ago' '+%Y-%m-%d' 2>/dev/null || date -v-30d '+%Y-%m-%d')\n\n # Search for PRs from copilot/* branches in the last 30 days using gh CLI\n # Using branch prefix search (head:copilot/) instead of author for reliability\n echo \"Fetching Copilot PRs from the last 30 days...\"\n FETCH_TMP=\"${RUNNER_TEMP:-/tmp}/copilot-prs-fetch.json\"\n rm -f \"$FETCH_TMP\"\n FETCH_OK=true\n gh pr list --repo \"$GITHUB_REPOSITORY\" \\\n --search \"head:copilot/ created:>=${DATE_30_DAYS_AGO}\" \\\n --state all \\\n --json number,title,author,headRefName,createdAt,state,url,body,labels,updatedAt,closedAt,mergedAt \\\n --limit 1000 \\\n > \"$FETCH_TMP\" || FETCH_OK=false\n\n if [ \"$FETCH_OK\" != \"true\" ] || ! jq -e 'type == \"array\"' \"$FETCH_TMP\" >/dev/null 2>&1; then\n # Transient GitHub API failures (e.g. 503) must not fail the whole run when\n # stale cached data is still available; fall back to it instead.\n if [ -s \"$CACHE_FILE\" ]; then\n echo \"::warning::Failed to fetch Copilot PR data; falling back to stale cached data\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n echo \"Total PRs in stale cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\n echo \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\n echo \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n exit 0\n fi\n echo \"::error::Failed to fetch Copilot PR data and no cached data is available\"\n exit 1\n fi\n\n cp \"$FETCH_TMP\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n rm -f \"$FETCH_TMP\"\n\n # Generate schema for reference\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n\n # Store in cache under stable names so future runs can reuse it on any date\n cp /tmp/gh-aw/agent/pr-data/copilot-prs.json \"$CACHE_FILE\"\n cp /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json \"$CACHE_SCHEMA_FILE\"\n\n # Drop legacy date-keyed cache entries so the cache does not grow unbounded\n rm -f \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9].json \\\n \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]-schema.json 2>/dev/null || true\n\n echo \"✓ PR data saved to cache: $(basename \"$CACHE_FILE\")\"\n echo \"Total PRs found: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nfi\n\n# Always ensure data is available at expected locations for backward compatibility\necho \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\necho \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/copilot-pr-prompt-analysis.lock.yml b/.github/workflows/copilot-pr-prompt-analysis.lock.yml index 95de1212f6c..70dada575a6 100644 --- a/.github/workflows/copilot-pr-prompt-analysis.lock.yml +++ b/.github/workflows/copilot-pr-prompt-analysis.lock.yml @@ -27,13 +27,13 @@ # # Resolved workflow manifest: # Imports: -# - shared/daily-audit-discussion.md # - shared/repo-memory-standard.md -# - shared/copilot-pr-data-fetch.md # - shared/reporting.md -# - shared/copilot-pr-analysis-base.md # - shared/otlp.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md +# - shared/copilot-pr-data-fetch.md +# - shared/copilot-pr-analysis-base.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/copilot-session-insights.lock.yml b/.github/workflows/copilot-session-insights.lock.yml index 7ff426e1764..b6302bf7540 100644 --- a/.github/workflows/copilot-session-insights.lock.yml +++ b/.github/workflows/copilot-session-insights.lock.yml @@ -28,16 +28,16 @@ # Resolved workflow manifest: # Imports: # - shared/mcp-pagination.md -# - shared/daily-audit-discussion.md # - shared/repo-memory-standard.md # - ../skills/jqschema/SKILL.md # - shared/copilot-session-data-fetch.md -# - shared/python-dataviz.md -# - shared/session-analysis-charts.md # - shared/session-analysis-strategies.md # - shared/reporting.md # - shared/otlp.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md +# - shared/python-dataviz.md +# - shared/session-analysis-charts.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/daily-architecture-diagram.lock.yml b/.github/workflows/daily-architecture-diagram.lock.yml index f6594731b82..77040434559 100644 --- a/.github/workflows/daily-architecture-diagram.lock.yml +++ b/.github/workflows/daily-architecture-diagram.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-cli-performance.lock.yml b/.github/workflows/daily-cli-performance.lock.yml index 6c51ac652a9..63fe97aff14 100644 --- a/.github/workflows/daily-cli-performance.lock.yml +++ b/.github/workflows/daily-cli-performance.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/mcp-pagination.md -# - shared/daily-audit-discussion.md -# - shared/reporting.md # - shared/go-make.md # - shared/otlp.md +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-cli-tools-tester.lock.yml b/.github/workflows/daily-cli-tools-tester.lock.yml index 36351c15d14..f32a8c6682e 100644 --- a/.github/workflows/daily-cli-tools-tester.lock.yml +++ b/.github/workflows/daily-cli-tools-tester.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-code-metrics.lock.yml b/.github/workflows/daily-code-metrics.lock.yml index c06d3b8816b..b91bda9c45d 100644 --- a/.github/workflows/daily-code-metrics.lock.yml +++ b/.github/workflows/daily-code-metrics.lock.yml @@ -28,12 +28,12 @@ # Resolved workflow manifest: # Imports: # - shared/crush.md +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/daily-audit-base.md # - shared/python-dataviz.md # - shared/trends.md -# - shared/otlp.md -# - shared/daily-audit-base.md # # Secrets used: # - DOCKER_PAT diff --git a/.github/workflows/daily-compiler-quality.lock.yml b/.github/workflows/daily-compiler-quality.lock.yml index f3319009d5e..868c1fc59a9 100644 --- a/.github/workflows/daily-compiler-quality.lock.yml +++ b/.github/workflows/daily-compiler-quality.lock.yml @@ -28,12 +28,12 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-discussion.md +# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md -# - shared/otlp.md -# - shared/daily-audit-base.md # # Secrets used: # - DOCKER_PAT diff --git a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml index 7d1582c9078..fcef34eac6b 100644 --- a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml +++ b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-doc-healer.lock.yml b/.github/workflows/daily-doc-healer.lock.yml index 337ce0a86ba..7c89a9e09a1 100644 --- a/.github/workflows/daily-doc-healer.lock.yml +++ b/.github/workflows/daily-doc-healer.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-experiment-report.lock.yml b/.github/workflows/daily-experiment-report.lock.yml index 310d4c234c3..f5b9f656895 100644 --- a/.github/workflows/daily-experiment-report.lock.yml +++ b/.github/workflows/daily-experiment-report.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/trending-charts-simple.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # diff --git a/.github/workflows/daily-file-diet.lock.yml b/.github/workflows/daily-file-diet.lock.yml index 1325a4246c6..113e004e1ef 100644 --- a/.github/workflows/daily-file-diet.lock.yml +++ b/.github/workflows/daily-file-diet.lock.yml @@ -28,14 +28,14 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md +# - shared/safe-output-app.md +# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md -# - shared/safe-output-app.md -# - shared/otlp.md # # Secrets used: # - DOCKER_PAT diff --git a/.github/workflows/daily-formal-spec-verifier.lock.yml b/.github/workflows/daily-formal-spec-verifier.lock.yml index 234530946cc..f3430761a78 100644 --- a/.github/workflows/daily-formal-spec-verifier.lock.yml +++ b/.github/workflows/daily-formal-spec-verifier.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md -# - shared/otlp.md # # Secrets used: # - GH_AW_AGENT_TOKEN diff --git a/.github/workflows/daily-function-namer.lock.yml b/.github/workflows/daily-function-namer.lock.yml index 976b1053481..c129a29b95a 100644 --- a/.github/workflows/daily-function-namer.lock.yml +++ b/.github/workflows/daily-function-namer.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md -# - shared/otlp.md -# - shared/daily-audit-base.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/daily-geo-optimizer.lock.yml b/.github/workflows/daily-geo-optimizer.lock.yml index 122c9e0ca02..f203caa8260 100644 --- a/.github/workflows/daily-geo-optimizer.lock.yml +++ b/.github/workflows/daily-geo-optimizer.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-graft-intelligence.lock.yml b/.github/workflows/daily-graft-intelligence.lock.yml index 752ba70ef4a..d3abd6c8d56 100644 --- a/.github/workflows/daily-graft-intelligence.lock.yml +++ b/.github/workflows/daily-graft-intelligence.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/activation-app.md -# - shared/reporting.md -# - shared/daily-issue-base.md # - shared/gh.md # - shared/mcp/graft.md # - shared/noop-reminder.md +# - shared/activation-app.md +# - shared/reporting.md +# - shared/daily-issue-base.md # # Secrets used: # - GH_AW_DEFAULT_OTLP_HEADERS diff --git a/.github/workflows/daily-issues-report.lock.yml b/.github/workflows/daily-issues-report.lock.yml index 9ffa3affd4a..57067937b26 100644 --- a/.github/workflows/daily-issues-report.lock.yml +++ b/.github/workflows/daily-issues-report.lock.yml @@ -28,15 +28,15 @@ # Resolved workflow manifest: # Imports: # - shared/github-guard-policy.md -# - shared/daily-audit-discussion.md -# - shared/reporting.md # - ../skills/jqschema/SKILL.md # - shared/issues-data-fetch.md -# - shared/python-dataviz.md -# - shared/trends.md # - shared/python-nlp.md # - shared/otlp.md +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - shared/daily-audit-base.md +# - shared/python-dataviz.md +# - shared/trends.md # # Secrets used: # - COPILOT_GITHUB_TOKEN @@ -665,6 +665,35 @@ jobs: GITHUB_GRAPHQL_URL: https://localhost:18443/api/graphql GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} NODE_EXTRA_CA_CERTS: /tmp/gh-aw/proxy-logs/proxy-tls/ca.crt + - name: Setup Python NLP environment + run: | + mkdir -p /tmp/gh-aw/python/{data,charts,artifacts} + # Create a virtual environment for proper package isolation (avoids --break-system-packages) + # Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/) + # Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC). + # This must match shared/python-dataviz.md so either import can create the shared environment first. + if [ ! -d /tmp/gh-aw/python/venv ]; then + uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv + fi + echo "/tmp/gh-aw/python/venv/bin" >> "$GITHUB_PATH" + /tmp/gh-aw/python/venv/bin/pip install --quiet nltk scikit-learn textblob wordcloud + + # Download required NLTK corpora + /tmp/gh-aw/python/venv/bin/python3 -c " + import nltk + for corpus in ['punkt_tab', 'stopwords', 'vader_lexicon', 'averaged_perceptron_tagger_eng']: + nltk.download(corpus, quiet=True) + print('NLTK corpora ready') + " + + /tmp/gh-aw/python/venv/bin/python3 -c "import sklearn; print(f'scikit-learn {sklearn.__version__}')" + env: + GH_HOST: ${{ env.GH_HOST || 'github.com' }} + GH_REPO: ${{ github.repository }} + GITHUB_API_URL: https://localhost:18443/api/v3 + GITHUB_GRAPHQL_URL: https://localhost:18443/api/graphql + NODE_EXTRA_CA_CERTS: /tmp/gh-aw/proxy-logs/proxy-tls/ca.crt + UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python - name: Setup Python environment run: | # Create working directory for Python scripts @@ -727,35 +756,6 @@ jobs: /tmp/gh-aw/python/*.py /tmp/gh-aw/python/data/* retention-days: 30 - - name: Setup Python NLP environment - run: | - mkdir -p /tmp/gh-aw/python/{data,charts,artifacts} - # Create a virtual environment for proper package isolation (avoids --break-system-packages) - # Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/) - # Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC). - # This must match shared/python-dataviz.md so either import can create the shared environment first. - if [ ! -d /tmp/gh-aw/python/venv ]; then - uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv - fi - echo "/tmp/gh-aw/python/venv/bin" >> "$GITHUB_PATH" - /tmp/gh-aw/python/venv/bin/pip install --quiet nltk scikit-learn textblob wordcloud - - # Download required NLTK corpora - /tmp/gh-aw/python/venv/bin/python3 -c " - import nltk - for corpus in ['punkt_tab', 'stopwords', 'vader_lexicon', 'averaged_perceptron_tagger_eng']: - nltk.download(corpus, quiet=True) - print('NLTK corpora ready') - " - - /tmp/gh-aw/python/venv/bin/python3 -c "import sklearn; print(f'scikit-learn {sklearn.__version__}')" - env: - GH_HOST: ${{ env.GH_HOST || 'github.com' }} - GH_REPO: ${{ github.repository }} - GITHUB_API_URL: https://localhost:18443/api/v3 - GITHUB_GRAPHQL_URL: https://localhost:18443/api/graphql - NODE_EXTRA_CA_CERTS: /tmp/gh-aw/proxy-logs/proxy-tls/ca.crt - UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python - name: Configure Git credentials env: GITHUB_REPOSITORY: ${{ github.repository }} diff --git a/.github/workflows/daily-malicious-code-scan.lock.yml b/.github/workflows/daily-malicious-code-scan.lock.yml index 2cb7befd963..71512ac17f8 100644 --- a/.github/workflows/daily-malicious-code-scan.lock.yml +++ b/.github/workflows/daily-malicious-code-scan.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/security-analysis-base.md +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml index ab004e8382b..1cd423c7ac3 100644 --- a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml +++ b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md -# - shared/daily-audit-discussion.md # - shared/safe-output-app.md # - shared/mcp/serena.md # - shared/otlp.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-multi-device-docs-tester.lock.yml b/.github/workflows/daily-multi-device-docs-tester.lock.yml index 4954d7b98c4..585d151885a 100644 --- a/.github/workflows/daily-multi-device-docs-tester.lock.yml +++ b/.github/workflows/daily-multi-device-docs-tester.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-news.lock.yml b/.github/workflows/daily-news.lock.yml index 3bbf9448469..1cdfe7232b1 100644 --- a/.github/workflows/daily-news.lock.yml +++ b/.github/workflows/daily-news.lock.yml @@ -30,12 +30,12 @@ # - shared/repo-memory-standard.md # - shared/mcp/tavily.md # - ../skills/jqschema/SKILL.md -# - shared/daily-audit-discussion.md -# - shared/python-dataviz.md -# - shared/trends.md # - shared/otlp.md # - shared/reporting.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md +# - shared/python-dataviz.md +# - shared/trends.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/daily-observability-report.lock.yml b/.github/workflows/daily-observability-report.lock.yml index 4ce473a6ccb..7206e0d4228 100644 --- a/.github/workflows/daily-observability-report.lock.yml +++ b/.github/workflows/daily-observability-report.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/meta-analysis-base.md -# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-performance-summary.lock.yml b/.github/workflows/daily-performance-summary.lock.yml index 7ce38a27a55..f16529ceade 100644 --- a/.github/workflows/daily-performance-summary.lock.yml +++ b/.github/workflows/daily-performance-summary.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/trending-charts-simple.md -# - shared/daily-audit-discussion.md # - shared/github-queries-mcp-script.md # - shared/reporting.md # - shared/otlp.md +# - shared/trending-charts-simple.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # diff --git a/.github/workflows/daily-regulatory.lock.yml b/.github/workflows/daily-regulatory.lock.yml index 9b7eea027c2..2159e5d3e65 100644 --- a/.github/workflows/daily-regulatory.lock.yml +++ b/.github/workflows/daily-regulatory.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/daily-audit-discussion.md # - shared/github-queries-mcp-script.md # - shared/reporting.md # - shared/otlp.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-reliability-review.lock.yml b/.github/workflows/daily-reliability-review.lock.yml index 765eaf6bd4d..bcc68e1d417 100644 --- a/.github/workflows/daily-reliability-review.lock.yml +++ b/.github/workflows/daily-reliability-review.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/opencode.md -# - shared/activation-app.md # - shared/sentry.md # - shared/mcp/sentry.md # - shared/reporting.md +# - shared/activation-app.md # - shared/daily-issue-base.md # # Secrets used: diff --git a/.github/workflows/daily-rendering-scripts-verifier.lock.yml b/.github/workflows/daily-rendering-scripts-verifier.lock.yml index 98dab9c9342..dae56e9884f 100644 --- a/.github/workflows/daily-rendering-scripts-verifier.lock.yml +++ b/.github/workflows/daily-rendering-scripts-verifier.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/meta-analysis-base.md # - shared/skip-if-issue-open.md +# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md # - shared/daily-audit-discussion.md -# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-repo-chronicle.lock.yml b/.github/workflows/daily-repo-chronicle.lock.yml index 3b06e6ebc0a..8ea362d807f 100644 --- a/.github/workflows/daily-repo-chronicle.lock.yml +++ b/.github/workflows/daily-repo-chronicle.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/daily-audit-discussion.md -# - shared/python-dataviz.md -# - shared/trends.md # - shared/otlp.md # - shared/reporting.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md +# - shared/python-dataviz.md +# - shared/trends.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/daily-safe-output-integrator.lock.yml b/.github/workflows/daily-safe-output-integrator.lock.yml index 193fe6757be..34a6eb540ea 100644 --- a/.github/workflows/daily-safe-output-integrator.lock.yml +++ b/.github/workflows/daily-safe-output-integrator.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-safe-output-optimizer.lock.yml b/.github/workflows/daily-safe-output-optimizer.lock.yml index 7d5b34a33a7..8618a793fcc 100644 --- a/.github/workflows/daily-safe-output-optimizer.lock.yml +++ b/.github/workflows/daily-safe-output-optimizer.lock.yml @@ -31,9 +31,9 @@ # - shared/aw-logs-24h-fetch-setup.md # - shared/activation-app.md # - ../skills/jqschema/SKILL.md -# - shared/daily-audit-discussion.md # - shared/otlp.md # - shared/reporting.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-safe-outputs-conformance.lock.yml b/.github/workflows/daily-safe-outputs-conformance.lock.yml index 7409fa056be..88b98e86620 100644 --- a/.github/workflows/daily-safe-outputs-conformance.lock.yml +++ b/.github/workflows/daily-safe-outputs-conformance.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-secrets-analysis.lock.yml b/.github/workflows/daily-secrets-analysis.lock.yml index 2d7f2590e6e..35cfa61be32 100644 --- a/.github/workflows/daily-secrets-analysis.lock.yml +++ b/.github/workflows/daily-secrets-analysis.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/daily-audit-discussion.md # - shared/otlp.md # - shared/reporting.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-security-observability.lock.yml b/.github/workflows/daily-security-observability.lock.yml index efad2330095..745ae8987a8 100644 --- a/.github/workflows/daily-security-observability.lock.yml +++ b/.github/workflows/daily-security-observability.lock.yml @@ -28,11 +28,11 @@ # Resolved workflow manifest: # Imports: # - shared/meta-analysis-base.md +# - shared/python-dataviz.md +# - shared/otlp.md # - shared/trending-charts-simple.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/python-dataviz.md -# - shared/otlp.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # @@ -570,32 +570,32 @@ jobs: with: key: agentic-logs path: .github/aw/logs + - name: Setup Python environment + run: "# Create working directory for Python scripts\nmkdir -p /tmp/gh-aw/python\nmkdir -p /tmp/gh-aw/python/data\nmkdir -p /tmp/gh-aw/python/charts\nmkdir -p /tmp/gh-aw/python/artifacts\n\necho \"Python environment setup complete\"\necho \"Working directory: /tmp/gh-aw/python\"\necho \"Data directory: /tmp/gh-aw/python/data\"\necho \"Charts directory: /tmp/gh-aw/python/charts\"\necho \"Artifacts directory: /tmp/gh-aw/python/artifacts\"\n" - env: UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python - name: Setup Python environment - run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/python/{data,charts,artifacts}\n# The agent sandbox cannot run the runner's CPython (glibc mismatch) and only ships\n# PyPy, which has no wheels for the chart libraries — installing them from inside the\n# sandbox builds NumPy/SciPy from source and exhausts the runner disk. Install a\n# portable uv-managed CPython plus the chart libraries under /tmp/gh-aw, which is\n# mounted read-write into the sandbox, so the agent can import them directly.\n# This must match shared/python-dataviz.md and shared/python-nlp.md so either import can\n# create the shared environment first; never recreate it, or a sibling import's packages\n# (for example the NLP libraries) would be discarded.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\nuv pip install --quiet --python /tmp/gh-aw/python/venv/bin/python numpy pandas matplotlib seaborn scipy\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/python -c \"import numpy,pandas,matplotlib,seaborn,scipy;print('chart-libraries-ready')\"\n" + name: Install Python scientific libraries + run: "# Create a virtual environment for proper package isolation (avoids --break-system-packages)\n# Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/)\n# Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC).\n# This must match shared/python-nlp.md so either import can create the shared environment first.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/pip install --quiet numpy pandas matplotlib seaborn scipy\n\n# Verify installations\n/tmp/gh-aw/python/venv/bin/python3 -c \"import numpy; print(f'NumPy {numpy.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import pandas; print(f'Pandas {pandas.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import matplotlib; print(f'Matplotlib {matplotlib.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import seaborn; print(f'Seaborn {seaborn.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import scipy; print(f'SciPy {scipy.__version__} installed')\"\n\necho \"All scientific libraries installed successfully\"\n" - if: always() name: Upload source files and data uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: if-no-files-found: warn - name: trending-source-and-data + name: python-source-and-data path: | /tmp/gh-aw/python/*.py /tmp/gh-aw/python/data/* retention-days: 30 - - name: Setup Python environment - run: "# Create working directory for Python scripts\nmkdir -p /tmp/gh-aw/python\nmkdir -p /tmp/gh-aw/python/data\nmkdir -p /tmp/gh-aw/python/charts\nmkdir -p /tmp/gh-aw/python/artifacts\n\necho \"Python environment setup complete\"\necho \"Working directory: /tmp/gh-aw/python\"\necho \"Data directory: /tmp/gh-aw/python/data\"\necho \"Charts directory: /tmp/gh-aw/python/charts\"\necho \"Artifacts directory: /tmp/gh-aw/python/artifacts\"\n" - env: UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python - name: Install Python scientific libraries - run: "# Create a virtual environment for proper package isolation (avoids --break-system-packages)\n# Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/)\n# Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC).\n# This must match shared/python-nlp.md so either import can create the shared environment first.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/pip install --quiet numpy pandas matplotlib seaborn scipy\n\n# Verify installations\n/tmp/gh-aw/python/venv/bin/python3 -c \"import numpy; print(f'NumPy {numpy.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import pandas; print(f'Pandas {pandas.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import matplotlib; print(f'Matplotlib {matplotlib.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import seaborn; print(f'Seaborn {seaborn.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import scipy; print(f'SciPy {scipy.__version__} installed')\"\n\necho \"All scientific libraries installed successfully\"\n" + name: Setup Python environment + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/python/{data,charts,artifacts}\n# The agent sandbox cannot run the runner's CPython (glibc mismatch) and only ships\n# PyPy, which has no wheels for the chart libraries — installing them from inside the\n# sandbox builds NumPy/SciPy from source and exhausts the runner disk. Install a\n# portable uv-managed CPython plus the chart libraries under /tmp/gh-aw, which is\n# mounted read-write into the sandbox, so the agent can import them directly.\n# This must match shared/python-dataviz.md and shared/python-nlp.md so either import can\n# create the shared environment first; never recreate it, or a sibling import's packages\n# (for example the NLP libraries) would be discarded.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\nuv pip install --quiet --python /tmp/gh-aw/python/venv/bin/python numpy pandas matplotlib seaborn scipy\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/python -c \"import numpy,pandas,matplotlib,seaborn,scipy;print('chart-libraries-ready')\"\n" - if: always() name: Upload source files and data uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: if-no-files-found: warn - name: python-source-and-data + name: trending-source-and-data path: | /tmp/gh-aw/python/*.py /tmp/gh-aw/python/data/* diff --git a/.github/workflows/daily-security-red-team.lock.yml b/.github/workflows/daily-security-red-team.lock.yml index b1b51f31676..75d1fc0498f 100644 --- a/.github/workflows/daily-security-red-team.lock.yml +++ b/.github/workflows/daily-security-red-team.lock.yml @@ -29,9 +29,9 @@ # Imports: # - shared/opencode.md # - shared/security-analysis-base.md -# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-spdd-spec-planner.lock.yml b/.github/workflows/daily-spdd-spec-planner.lock.yml index e02b6dad301..886065e7fb0 100644 --- a/.github/workflows/daily-spdd-spec-planner.lock.yml +++ b/.github/workflows/daily-spdd-spec-planner.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md -# - shared/otlp.md # # Secrets used: # - GH_AW_AGENT_TOKEN diff --git a/.github/workflows/daily-team-evolution-insights.lock.yml b/.github/workflows/daily-team-evolution-insights.lock.yml index 04806f0977d..3bf7ec3f8c6 100644 --- a/.github/workflows/daily-team-evolution-insights.lock.yml +++ b/.github/workflows/daily-team-evolution-insights.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/goose.md -# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-testify-uber-super-expert.lock.yml b/.github/workflows/daily-testify-uber-super-expert.lock.yml index 1af4f2d3679..238797097cf 100644 --- a/.github/workflows/daily-testify-uber-super-expert.lock.yml +++ b/.github/workflows/daily-testify-uber-super-expert.lock.yml @@ -28,14 +28,14 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md +# - shared/safe-output-app.md +# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md -# - shared/safe-output-app.md -# - shared/otlp.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/daily-token-consumption-report.lock.yml b/.github/workflows/daily-token-consumption-report.lock.yml index 1b93fc97525..1dfb84324ff 100644 --- a/.github/workflows/daily-token-consumption-report.lock.yml +++ b/.github/workflows/daily-token-consumption-report.lock.yml @@ -30,9 +30,9 @@ # - shared/goose.md # - shared/mcp/sentry.md # - shared/mcp/grafana.md -# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/dead-code-remover.lock.yml b/.github/workflows/dead-code-remover.lock.yml index 6ada4394113..1bfcbbbe0af 100644 --- a/.github/workflows/dead-code-remover.lock.yml +++ b/.github/workflows/dead-code-remover.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md +# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md -# - shared/otlp.md # # Secrets used: # - GH_AW_CI_TRIGGER_TOKEN diff --git a/.github/workflows/delight.lock.yml b/.github/workflows/delight.lock.yml index f0f58b43bb6..a77a7c37639 100644 --- a/.github/workflows/delight.lock.yml +++ b/.github/workflows/delight.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md -# - shared/daily-audit-discussion.md # - shared/repo-memory-standard.md # - shared/otlp.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/dependabot-burner.lock.yml b/.github/workflows/dependabot-burner.lock.yml index 6b28bc32b5a..bb2475fbd10 100644 --- a/.github/workflows/dependabot-burner.lock.yml +++ b/.github/workflows/dependabot-burner.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/mcp-pagination.md -# - shared/activation-app.md # - shared/otlp.md # - shared/reporting.md +# - shared/activation-app.md # - shared/daily-pr-base.md # # Secrets used: diff --git a/.github/workflows/detection-analysis-report.lock.yml b/.github/workflows/detection-analysis-report.lock.yml index 7265204fb92..8a05673c5fb 100644 --- a/.github/workflows/detection-analysis-report.lock.yml +++ b/.github/workflows/detection-analysis-report.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: +# - shared/aw-logs-24h-fetch-setup.md +# - shared/reporting.md # - shared/trending-charts-simple.md # - shared/daily-audit-discussion.md # - shared/otlp.md -# - shared/aw-logs-24h-fetch-setup.md -# - shared/reporting.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # @@ -561,6 +561,10 @@ jobs: with: key: agentic-logs path: .github/aw/logs + - env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + name: Download logs from last 24 hours + run: ./gh-aw logs --start-date -1d --count 3000 -o /tmp/gh-aw/aw-mcp/logs - env: UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python name: Setup Python environment @@ -575,10 +579,6 @@ jobs: /tmp/gh-aw/python/*.py /tmp/gh-aw/python/data/* retention-days: 30 - - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Download logs from last 24 hours - run: ./gh-aw logs --start-date -1d --count 3000 -o /tmp/gh-aw/aw-mcp/logs - name: Configure Git credentials env: diff --git a/.github/workflows/developer-docs-consolidator.lock.yml b/.github/workflows/developer-docs-consolidator.lock.yml index ecf06e0d4df..d822e9a4208 100644 --- a/.github/workflows/developer-docs-consolidator.lock.yml +++ b/.github/workflows/developer-docs-consolidator.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md -# - shared/otlp.md -# - shared/daily-audit-base.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/docs-noob-tester.lock.yml b/.github/workflows/docs-noob-tester.lock.yml index d4b45c5f3b3..9b36fd03f53 100644 --- a/.github/workflows/docs-noob-tester.lock.yml +++ b/.github/workflows/docs-noob-tester.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/daily-audit-discussion.md -# - shared/reporting.md # - shared/docs-server-lifecycle.md # - shared/keep-it-short.md # - shared/otlp.md +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/duplicate-code-detector.lock.yml b/.github/workflows/duplicate-code-detector.lock.yml index 1dd91994649..7ffdfeb44f9 100644 --- a/.github/workflows/duplicate-code-detector.lock.yml +++ b/.github/workflows/duplicate-code-detector.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # - shared/otlp.md # - shared/reporting.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # - shared/go-source-analysis.md # # Secrets used: diff --git a/.github/workflows/eslint-refiner.lock.yml b/.github/workflows/eslint-refiner.lock.yml index f2d9a2e18bb..6d4426e3c12 100644 --- a/.github/workflows/eslint-refiner.lock.yml +++ b/.github/workflows/eslint-refiner.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/daily-audit-discussion.md # - shared/otlp.md # - shared/reporting.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/example-workflow-analyzer.lock.yml b/.github/workflows/example-workflow-analyzer.lock.yml index a00b8d8dd5c..e9f542eb292 100644 --- a/.github/workflows/example-workflow-analyzer.lock.yml +++ b/.github/workflows/example-workflow-analyzer.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/meta-analysis-base.md +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/github-mcp-structural-analysis.lock.yml b/.github/workflows/github-mcp-structural-analysis.lock.yml index e3886135f73..8315b867abc 100644 --- a/.github/workflows/github-mcp-structural-analysis.lock.yml +++ b/.github/workflows/github-mcp-structural-analysis.lock.yml @@ -29,10 +29,10 @@ # Imports: # - shared/mcp-pagination.md # - shared/github-mcp-pagination-wrappers.md -# - shared/daily-audit-discussion.md -# - shared/reporting.md # - shared/python-dataviz.md # - shared/otlp.md +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/github-mcp-tools-report.lock.yml b/.github/workflows/github-mcp-tools-report.lock.yml index c69516ecd1a..07092fd077a 100644 --- a/.github/workflows/github-mcp-tools-report.lock.yml +++ b/.github/workflows/github-mcp-tools-report.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/github-remote-mcp-auth-test.lock.yml b/.github/workflows/github-remote-mcp-auth-test.lock.yml index 7903913f832..13e42c38cd9 100644 --- a/.github/workflows/github-remote-mcp-auth-test.lock.yml +++ b/.github/workflows/github-remote-mcp-auth-test.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/glossary-maintainer.lock.yml b/.github/workflows/glossary-maintainer.lock.yml index ee479405499..db9326dd977 100644 --- a/.github/workflows/glossary-maintainer.lock.yml +++ b/.github/workflows/glossary-maintainer.lock.yml @@ -30,10 +30,10 @@ # - ../skills/documentation/SKILL.md # - ../agents/technical-doc-writer.agent.md # - shared/ai-coding-dictionary.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # - shared/otlp.md # - shared/reporting.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/go-fan.lock.yml b/.github/workflows/go-fan.lock.yml index e2f7f832b8c..743d1eb4f1d 100644 --- a/.github/workflows/go-fan.lock.yml +++ b/.github/workflows/go-fan.lock.yml @@ -27,13 +27,13 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md -# - shared/otlp.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/grumpy-reviewer.lock.yml b/.github/workflows/grumpy-reviewer.lock.yml index b19f3489aeb..b3da46a1ce7 100644 --- a/.github/workflows/grumpy-reviewer.lock.yml +++ b/.github/workflows/grumpy-reviewer.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md -# - shared/otlp.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/impeccable-skills-reviewer.lock.yml b/.github/workflows/impeccable-skills-reviewer.lock.yml index 3d2e68ae6a5..1488bbe9843 100644 --- a/.github/workflows/impeccable-skills-reviewer.lock.yml +++ b/.github/workflows/impeccable-skills-reviewer.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/github-guard-policy.md -# - shared/pr-code-review-config.md -# - shared/pr-review-base.md # - shared/reporting.md # - shared/otlp.md # - shared/pr-diff-data-fetch.md +# - shared/github-guard-policy.md +# - shared/pr-code-review-config.md +# - shared/pr-review-base.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/linter-miner.lock.yml b/.github/workflows/linter-miner.lock.yml index aaffd8453cf..649a2f444c7 100644 --- a/.github/workflows/linter-miner.lock.yml +++ b/.github/workflows/linter-miner.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # - shared/otlp.md # - shared/reporting.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # # Secrets used: # - DOCKER_PAT diff --git a/.github/workflows/lockfile-stats.lock.yml b/.github/workflows/lockfile-stats.lock.yml index 1e127515bf3..206aba3b605 100644 --- a/.github/workflows/lockfile-stats.lock.yml +++ b/.github/workflows/lockfile-stats.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/mattpocock-skills-reviewer.lock.yml b/.github/workflows/mattpocock-skills-reviewer.lock.yml index 9a1dc908393..1533e9e01c3 100644 --- a/.github/workflows/mattpocock-skills-reviewer.lock.yml +++ b/.github/workflows/mattpocock-skills-reviewer.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md +# - shared/pr-diff-data-fetch.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md -# - shared/otlp.md -# - shared/pr-diff-data-fetch.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/mcp-inspector.lock.yml b/.github/workflows/mcp-inspector.lock.yml index 9505ddfddb9..814a3ae9d19 100644 --- a/.github/workflows/mcp-inspector.lock.yml +++ b/.github/workflows/mcp-inspector.lock.yml @@ -27,8 +27,6 @@ # # Resolved workflow manifest: # Imports: -# - shared/daily-audit-discussion.md -# - shared/reporting.md # - shared/mcp/ast-grep.md # - shared/mcp/datadog.md # - shared/mcp/deepwiki.md @@ -36,10 +34,12 @@ # - shared/mcp/sentry.md # - shared/mcp/slack.md # - shared/mcp/tavily.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # - shared/otlp.md +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - shared/daily-audit-base.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/ponytail-reviewer.lock.yml b/.github/workflows/ponytail-reviewer.lock.yml index c682e7c399d..1083e1be057 100644 --- a/.github/workflows/ponytail-reviewer.lock.yml +++ b/.github/workflows/ponytail-reviewer.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md +# - shared/pr-diff-data-fetch.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md -# - shared/otlp.md -# - shared/pr-diff-data-fetch.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/portfolio-analyst.lock.yml b/.github/workflows/portfolio-analyst.lock.yml index cdf49cc2069..376598e751d 100644 --- a/.github/workflows/portfolio-analyst.lock.yml +++ b/.github/workflows/portfolio-analyst.lock.yml @@ -29,9 +29,9 @@ # Imports: # - shared/mcp/sentry.md # - shared/mcp/grafana.md +# - shared/reporting.md # - shared/python-dataviz.md # - shared/trends.md -# - shared/reporting.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/pr-code-quality-reviewer.lock.yml b/.github/workflows/pr-code-quality-reviewer.lock.yml index b8eb8eb118e..735c67759e7 100644 --- a/.github/workflows/pr-code-quality-reviewer.lock.yml +++ b/.github/workflows/pr-code-quality-reviewer.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md +# - shared/pr-diff-data-fetch.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md -# - shared/otlp.md -# - shared/pr-diff-data-fetch.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/pr-nitpick-reviewer.lock.yml b/.github/workflows/pr-nitpick-reviewer.lock.yml index 2d7a564fba9..c494b019cfc 100644 --- a/.github/workflows/pr-nitpick-reviewer.lock.yml +++ b/.github/workflows/pr-nitpick-reviewer.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: +# - shared/reporting.md +# - shared/otlp.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md -# - shared/reporting.md -# - shared/otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/pr-triage-agent.lock.yml b/.github/workflows/pr-triage-agent.lock.yml index 21c1c313d2c..7db7fc7381f 100644 --- a/.github/workflows/pr-triage-agent.lock.yml +++ b/.github/workflows/pr-triage-agent.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md +# - shared/otlp.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md -# - shared/otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/prompt-clustering-analysis.lock.yml b/.github/workflows/prompt-clustering-analysis.lock.yml index d6a243d1331..9d0883e8f7c 100644 --- a/.github/workflows/prompt-clustering-analysis.lock.yml +++ b/.github/workflows/prompt-clustering-analysis.lock.yml @@ -28,13 +28,13 @@ # Resolved workflow manifest: # Imports: # - shared/meta-analysis-base.md -# - shared/trending-charts-simple.md -# - shared/daily-audit-discussion.md -# - shared/reporting.md # - ../skills/jqschema/SKILL.md # - shared/copilot-pr-data-fetch.md # - shared/python-nlp.md # - shared/otlp.md +# - shared/trending-charts-simple.md +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # @@ -570,6 +570,18 @@ jobs: with: key: agentic-logs path: .github/aw/logs + - name: Install gh CLI + run: | + bash "${RUNNER_TEMP}/gh-aw/actions/install_gh_cli.sh" + - env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + name: Fetch Copilot PR data + run: "# Create output directories\nmkdir -p /tmp/gh-aw/agent/pr-data\nmkdir -p /tmp/gh-aw/cache-memory\n\n# Cache files use stable names so restored caches from previous runs are reusable\n# regardless of the date they were written on. Freshness is decided by file age.\nCACHE_DIR=\"/tmp/gh-aw/cache-memory\"\nCACHE_FILE=\"$CACHE_DIR/copilot-prs-latest.json\"\nCACHE_SCHEMA_FILE=\"$CACHE_DIR/copilot-prs-latest-schema.json\"\nCACHE_MAX_AGE_SECONDS=\"${CACHE_MAX_AGE_SECONDS:-21600}\"\n\n# Returns success when the file exists, is non-empty and younger than the max age.\ncache_is_fresh() {\n cache_path=\"$1\"\n [ -s \"$cache_path\" ] || return 1\n cache_mtime=$(date -r \"$cache_path\" '+%s' 2>/dev/null) || return 1\n [ -n \"$cache_mtime\" ] || return 1\n now=$(date '+%s')\n [ \"$((now - cache_mtime))\" -lt \"$CACHE_MAX_AGE_SECONDS\" ]\n}\n\n# Check if restored cache data is still fresh enough to reuse\nif cache_is_fresh \"$CACHE_FILE\"; then\n CACHE_AGE_MINUTES=$(( ( $(date '+%s') - $(date -r \"$CACHE_FILE\" '+%s') ) / 60 ))\n echo \"✓ Found cached PR data (${CACHE_AGE_MINUTES} minutes old)\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n \n # Regenerate schema if missing\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n \n echo \"Using cached data written ${CACHE_AGE_MINUTES} minutes ago\"\n echo \"Total PRs in cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nelse\n echo \"⬇ Downloading fresh PR data...\"\n \n # Calculate date 30 days ago\n DATE_30_DAYS_AGO=$(date -d '30 days ago' '+%Y-%m-%d' 2>/dev/null || date -v-30d '+%Y-%m-%d')\n\n # Search for PRs from copilot/* branches in the last 30 days using gh CLI\n # Using branch prefix search (head:copilot/) instead of author for reliability\n echo \"Fetching Copilot PRs from the last 30 days...\"\n FETCH_TMP=\"${RUNNER_TEMP:-/tmp}/copilot-prs-fetch.json\"\n rm -f \"$FETCH_TMP\"\n FETCH_OK=true\n gh pr list --repo \"$GITHUB_REPOSITORY\" \\\n --search \"head:copilot/ created:>=${DATE_30_DAYS_AGO}\" \\\n --state all \\\n --json number,title,author,headRefName,createdAt,state,url,body,labels,updatedAt,closedAt,mergedAt \\\n --limit 1000 \\\n > \"$FETCH_TMP\" || FETCH_OK=false\n\n if [ \"$FETCH_OK\" != \"true\" ] || ! jq -e 'type == \"array\"' \"$FETCH_TMP\" >/dev/null 2>&1; then\n # Transient GitHub API failures (e.g. 503) must not fail the whole run when\n # stale cached data is still available; fall back to it instead.\n if [ -s \"$CACHE_FILE\" ]; then\n echo \"::warning::Failed to fetch Copilot PR data; falling back to stale cached data\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n echo \"Total PRs in stale cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\n echo \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\n echo \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n exit 0\n fi\n echo \"::error::Failed to fetch Copilot PR data and no cached data is available\"\n exit 1\n fi\n\n cp \"$FETCH_TMP\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n rm -f \"$FETCH_TMP\"\n\n # Generate schema for reference\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n\n # Store in cache under stable names so future runs can reuse it on any date\n cp /tmp/gh-aw/agent/pr-data/copilot-prs.json \"$CACHE_FILE\"\n cp /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json \"$CACHE_SCHEMA_FILE\"\n\n # Drop legacy date-keyed cache entries so the cache does not grow unbounded\n rm -f \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9].json \\\n \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]-schema.json 2>/dev/null || true\n\n echo \"✓ PR data saved to cache: $(basename \"$CACHE_FILE\")\"\n echo \"Total PRs found: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nfi\n\n# Always ensure data is available at expected locations for backward compatibility\necho \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\necho \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n" + - env: + UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python + name: Setup Python NLP environment + run: "mkdir -p /tmp/gh-aw/python/{data,charts,artifacts}\n# Create a virtual environment for proper package isolation (avoids --break-system-packages)\n# Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/)\n# Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC).\n# This must match shared/python-dataviz.md so either import can create the shared environment first.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/pip install --quiet nltk scikit-learn textblob wordcloud\n\n# Download required NLTK corpora\n/tmp/gh-aw/python/venv/bin/python3 -c \"\nimport nltk\nfor corpus in ['punkt_tab', 'stopwords', 'vader_lexicon', 'averaged_perceptron_tagger_eng']:\n nltk.download(corpus, quiet=True)\nprint('NLTK corpora ready')\n\"\n\n/tmp/gh-aw/python/venv/bin/python3 -c \"import sklearn; print(f'scikit-learn {sklearn.__version__}')\"\n" - env: UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python name: Setup Python environment @@ -584,18 +596,6 @@ jobs: /tmp/gh-aw/python/*.py /tmp/gh-aw/python/data/* retention-days: 30 - - name: Install gh CLI - run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_gh_cli.sh" - - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Fetch Copilot PR data - run: "# Create output directories\nmkdir -p /tmp/gh-aw/agent/pr-data\nmkdir -p /tmp/gh-aw/cache-memory\n\n# Cache files use stable names so restored caches from previous runs are reusable\n# regardless of the date they were written on. Freshness is decided by file age.\nCACHE_DIR=\"/tmp/gh-aw/cache-memory\"\nCACHE_FILE=\"$CACHE_DIR/copilot-prs-latest.json\"\nCACHE_SCHEMA_FILE=\"$CACHE_DIR/copilot-prs-latest-schema.json\"\nCACHE_MAX_AGE_SECONDS=\"${CACHE_MAX_AGE_SECONDS:-21600}\"\n\n# Returns success when the file exists, is non-empty and younger than the max age.\ncache_is_fresh() {\n cache_path=\"$1\"\n [ -s \"$cache_path\" ] || return 1\n cache_mtime=$(date -r \"$cache_path\" '+%s' 2>/dev/null) || return 1\n [ -n \"$cache_mtime\" ] || return 1\n now=$(date '+%s')\n [ \"$((now - cache_mtime))\" -lt \"$CACHE_MAX_AGE_SECONDS\" ]\n}\n\n# Check if restored cache data is still fresh enough to reuse\nif cache_is_fresh \"$CACHE_FILE\"; then\n CACHE_AGE_MINUTES=$(( ( $(date '+%s') - $(date -r \"$CACHE_FILE\" '+%s') ) / 60 ))\n echo \"✓ Found cached PR data (${CACHE_AGE_MINUTES} minutes old)\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n \n # Regenerate schema if missing\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n \n echo \"Using cached data written ${CACHE_AGE_MINUTES} minutes ago\"\n echo \"Total PRs in cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nelse\n echo \"⬇ Downloading fresh PR data...\"\n \n # Calculate date 30 days ago\n DATE_30_DAYS_AGO=$(date -d '30 days ago' '+%Y-%m-%d' 2>/dev/null || date -v-30d '+%Y-%m-%d')\n\n # Search for PRs from copilot/* branches in the last 30 days using gh CLI\n # Using branch prefix search (head:copilot/) instead of author for reliability\n echo \"Fetching Copilot PRs from the last 30 days...\"\n FETCH_TMP=\"${RUNNER_TEMP:-/tmp}/copilot-prs-fetch.json\"\n rm -f \"$FETCH_TMP\"\n FETCH_OK=true\n gh pr list --repo \"$GITHUB_REPOSITORY\" \\\n --search \"head:copilot/ created:>=${DATE_30_DAYS_AGO}\" \\\n --state all \\\n --json number,title,author,headRefName,createdAt,state,url,body,labels,updatedAt,closedAt,mergedAt \\\n --limit 1000 \\\n > \"$FETCH_TMP\" || FETCH_OK=false\n\n if [ \"$FETCH_OK\" != \"true\" ] || ! jq -e 'type == \"array\"' \"$FETCH_TMP\" >/dev/null 2>&1; then\n # Transient GitHub API failures (e.g. 503) must not fail the whole run when\n # stale cached data is still available; fall back to it instead.\n if [ -s \"$CACHE_FILE\" ]; then\n echo \"::warning::Failed to fetch Copilot PR data; falling back to stale cached data\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n echo \"Total PRs in stale cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\n echo \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\n echo \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n exit 0\n fi\n echo \"::error::Failed to fetch Copilot PR data and no cached data is available\"\n exit 1\n fi\n\n cp \"$FETCH_TMP\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n rm -f \"$FETCH_TMP\"\n\n # Generate schema for reference\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n\n # Store in cache under stable names so future runs can reuse it on any date\n cp /tmp/gh-aw/agent/pr-data/copilot-prs.json \"$CACHE_FILE\"\n cp /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json \"$CACHE_SCHEMA_FILE\"\n\n # Drop legacy date-keyed cache entries so the cache does not grow unbounded\n rm -f \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9].json \\\n \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]-schema.json 2>/dev/null || true\n\n echo \"✓ PR data saved to cache: $(basename \"$CACHE_FILE\")\"\n echo \"Total PRs found: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nfi\n\n# Always ensure data is available at expected locations for backward compatibility\necho \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\necho \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n" - - env: - UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python - name: Setup Python NLP environment - run: "mkdir -p /tmp/gh-aw/python/{data,charts,artifacts}\n# Create a virtual environment for proper package isolation (avoids --break-system-packages)\n# Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/)\n# Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC).\n# This must match shared/python-dataviz.md so either import can create the shared environment first.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/pip install --quiet nltk scikit-learn textblob wordcloud\n\n# Download required NLTK corpora\n/tmp/gh-aw/python/venv/bin/python3 -c \"\nimport nltk\nfor corpus in ['punkt_tab', 'stopwords', 'vader_lexicon', 'averaged_perceptron_tagger_eng']:\n nltk.download(corpus, quiet=True)\nprint('NLTK corpora ready')\n\"\n\n/tmp/gh-aw/python/venv/bin/python3 -c \"import sklearn; print(f'scikit-learn {sklearn.__version__}')\"\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/purelock.lock.yml b/.github/workflows/purelock.lock.yml index 9d77514ce15..bb1aae591b3 100644 --- a/.github/workflows/purelock.lock.yml +++ b/.github/workflows/purelock.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # - shared/otlp.md # - shared/reporting.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # # Secrets used: # - GH_AW_CI_TRIGGER_TOKEN diff --git a/.github/workflows/python-data-charts.lock.yml b/.github/workflows/python-data-charts.lock.yml index 556cc4335b7..20bf0513fe7 100644 --- a/.github/workflows/python-data-charts.lock.yml +++ b/.github/workflows/python-data-charts.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md +# - shared/reporting.md # - shared/python-dataviz.md # - shared/trends.md # - shared/charts-with-trending.md -# - shared/otlp.md -# - shared/reporting.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/refactoring-cadence.lock.yml b/.github/workflows/refactoring-cadence.lock.yml index 703667aa9b3..c49a4868593 100644 --- a/.github/workflows/refactoring-cadence.lock.yml +++ b/.github/workflows/refactoring-cadence.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md +# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md -# - shared/otlp.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/refiner.lock.yml b/.github/workflows/refiner.lock.yml index 5dc86fdaaed..d6580f86894 100644 --- a/.github/workflows/refiner.lock.yml +++ b/.github/workflows/refiner.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md +# - shared/reporting.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md -# - shared/otlp.md -# - shared/reporting.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/repo-audit-analyzer.lock.yml b/.github/workflows/repo-audit-analyzer.lock.yml index 56612705314..a913b4b590a 100644 --- a/.github/workflows/repo-audit-analyzer.lock.yml +++ b/.github/workflows/repo-audit-analyzer.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/mcp-pagination.md +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/repository-quality-improver.lock.yml b/.github/workflows/repository-quality-improver.lock.yml index 227954012cc..3ec43cddf5d 100644 --- a/.github/workflows/repository-quality-improver.lock.yml +++ b/.github/workflows/repository-quality-improver.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/daily-audit-discussion.md -# - shared/reporting.md # - shared/repository-quality-report-template.md # - shared/otlp.md +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/safe-output-health.lock.yml b/.github/workflows/safe-output-health.lock.yml index 133de8331af..793a31a7b03 100644 --- a/.github/workflows/safe-output-health.lock.yml +++ b/.github/workflows/safe-output-health.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/daily-audit-discussion.md -# - shared/reporting.md # - shared/aw-logs-24h-fetch.md # - ../skills/jqschema/SKILL.md # - shared/otlp.md +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/schema-consistency-checker.lock.yml b/.github/workflows/schema-consistency-checker.lock.yml index 0e3c67baf5b..b4e34873906 100644 --- a/.github/workflows/schema-consistency-checker.lock.yml +++ b/.github/workflows/schema-consistency-checker.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/security-review.lock.yml b/.github/workflows/security-review.lock.yml index 3dae057dfaf..d20f40c20a2 100644 --- a/.github/workflows/security-review.lock.yml +++ b/.github/workflows/security-review.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: +# - shared/security-analysis-base.md +# - shared/otlp.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md -# - shared/security-analysis-base.md -# - shared/otlp.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/semantic-function-refactor.lock.yml b/.github/workflows/semantic-function-refactor.lock.yml index 90b9db61784..7b6818fc569 100644 --- a/.github/workflows/semantic-function-refactor.lock.yml +++ b/.github/workflows/semantic-function-refactor.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # - shared/otlp.md # - shared/reporting.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # - shared/go-source-analysis.md # # Secrets used: diff --git a/.github/workflows/sergo.lock.yml b/.github/workflows/sergo.lock.yml index 6eef2f85eda..695d92ef510 100644 --- a/.github/workflows/sergo.lock.yml +++ b/.github/workflows/sergo.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/daily-audit-discussion.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # - shared/otlp.md # - shared/reporting.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/skillet.lock.yml b/.github/workflows/skillet.lock.yml index a1236419903..77193acf794 100644 --- a/.github/workflows/skillet.lock.yml +++ b/.github/workflows/skillet.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: +# - shared/otlp.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md -# - shared/otlp.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/slide-deck-maintainer.lock.yml b/.github/workflows/slide-deck-maintainer.lock.yml index 3ed5cc53696..216389d950f 100644 --- a/.github/workflows/slide-deck-maintainer.lock.yml +++ b/.github/workflows/slide-deck-maintainer.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md +# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md -# - shared/otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-codex.lock.yml b/.github/workflows/smoke-codex.lock.yml index bde14020b22..6b38265413f 100644 --- a/.github/workflows/smoke-codex.lock.yml +++ b/.github/workflows/smoke-codex.lock.yml @@ -28,15 +28,15 @@ # Resolved workflow manifest: # Imports: # - shared/gh.md -# - shared/reporting.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # - shared/trufflehog.md # - shared/otlp.md -# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md # - shared/playwright-title-test.md +# - shared/reporting.md +# - shared/reporting-otlp.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/smoke-copilot-aoai-apikey.lock.yml b/.github/workflows/smoke-copilot-aoai-apikey.lock.yml index 39e19bb8c23..f27a3cea2f1 100644 --- a/.github/workflows/smoke-copilot-aoai-apikey.lock.yml +++ b/.github/workflows/smoke-copilot-aoai-apikey.lock.yml @@ -31,11 +31,11 @@ # - shared/gh.md # - shared/reporting.md # - shared/github-queries-mcp-script.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # - shared/otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-copilot-aoai-entra.lock.yml b/.github/workflows/smoke-copilot-aoai-entra.lock.yml index e4ecc26890d..ea6097f1793 100644 --- a/.github/workflows/smoke-copilot-aoai-entra.lock.yml +++ b/.github/workflows/smoke-copilot-aoai-entra.lock.yml @@ -31,12 +31,12 @@ # - shared/gh.md # - shared/reporting.md # - shared/github-queries-mcp-script.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # - shared/otlp.md # - shared/token-telemetry-check.md # - shared/azure-auth.md # - shared/smoke-test-brevity.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # # Frontmatter env variables: # - AZURE_CONFIG_DIR: shared/azure-auth.md @@ -810,6 +810,11 @@ jobs: env: GH_AW_SKILL_DIR: ".github/skills" run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_skills.sh" + - env: + GH_AW_AZURE_CLIENT_ID: adb907fd-188c-4029-b67f-2559d96b2f1b + GH_AW_AZURE_TENANT_ID: 398a6654-997b-47e9-b12b-9515b896b4de + name: Re-authenticate Azure CLI with OIDC + run: "if [ -z \"$GH_AW_AZURE_OIDC_TOKEN_FILE\" ] || [ ! -f \"$GH_AW_AZURE_OIDC_TOKEN_FILE\" ]; then\n echo \"::error::Azure OIDC token file not found — the Fetch Azure OIDC token step may have failed\"\n exit 1\nfi\nmkdir -p \"$AZURE_CONFIG_DIR\"\nchmod 700 \"$AZURE_CONFIG_DIR\"\ncleanup() {\n rm -f \"$GH_AW_AZURE_OIDC_TOKEN_FILE\"\n}\ntrap cleanup EXIT\naz login --service-principal \\\n --username \"$GH_AW_AZURE_CLIENT_ID\" \\\n --tenant \"$GH_AW_AZURE_TENANT_ID\" \\\n --federated-token \"$(cat \"$GH_AW_AZURE_OIDC_TOKEN_FILE\")\" \\\n --output none \\\n --only-show-errors\naz account show --output table\n" - name: Setup Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: @@ -817,11 +822,6 @@ jobs: go-version-file: go.mod - name: Verify Go installation run: go version - - env: - GH_AW_AZURE_CLIENT_ID: adb907fd-188c-4029-b67f-2559d96b2f1b - GH_AW_AZURE_TENANT_ID: 398a6654-997b-47e9-b12b-9515b896b4de - name: Re-authenticate Azure CLI with OIDC - run: "if [ -z \"$GH_AW_AZURE_OIDC_TOKEN_FILE\" ] || [ ! -f \"$GH_AW_AZURE_OIDC_TOKEN_FILE\" ]; then\n echo \"::error::Azure OIDC token file not found — the Fetch Azure OIDC token step may have failed\"\n exit 1\nfi\nmkdir -p \"$AZURE_CONFIG_DIR\"\nchmod 700 \"$AZURE_CONFIG_DIR\"\ncleanup() {\n rm -f \"$GH_AW_AZURE_OIDC_TOKEN_FILE\"\n}\ntrap cleanup EXIT\naz login --service-principal \\\n --username \"$GH_AW_AZURE_CLIENT_ID\" \\\n --tenant \"$GH_AW_AZURE_TENANT_ID\" \\\n --federated-token \"$(cat \"$GH_AW_AZURE_OIDC_TOKEN_FILE\")\" \\\n --output none \\\n --only-show-errors\naz account show --output table\n" - name: Download container images run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.28.12@sha256:390051be4ed1847f774fd8980b61d3a3523574c0175d00c3fc7cdf2002a88202 ghcr.io/github/gh-aw-firewall/api-proxy:0.28.12@sha256:d7d533d87c80d87ff91ac0e21e9299055c3beedff1536262b97ed700fb065a32 ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.12@sha256:5250629d48eaedfedf2e948785228e8da29eec2a83cbab58ea0751c14a7b021d ghcr.io/github/gh-aw-firewall/squid:0.28.12@sha256:52c34aca98d2a6833c329f1505912a6949c4fda16618c010c979bd59ea99254f ghcr.io/github/gh-aw-mcpg:v0.4.14@sha256:b2f0c2b2f17b5fbe809e5bb99dc185b6ddd70df25295dc63a6d526350334eff5 ghcr.io/github/gh-aw-node@sha256:bac2192f6374d6262116399b34fc5e143d576f82719e90a18261cae7480f4d4e ghcr.io/github/github-mcp-server:v1.11.0@sha256:fbec75de11c255213fa08d80fb166abe73d851fff631c51c0079872967720699 ghcr.io/oraios/serena:1.7.0@sha256:6c9459e4246a39c9deaa4f23fb05a526ac6e237b24c8e84a927a098fa1ab6730 diff --git a/.github/workflows/smoke-copilot-arm.lock.yml b/.github/workflows/smoke-copilot-arm.lock.yml index d366980324f..1cde1a577b4 100644 --- a/.github/workflows/smoke-copilot-arm.lock.yml +++ b/.github/workflows/smoke-copilot-arm.lock.yml @@ -28,14 +28,14 @@ # Resolved workflow manifest: # Imports: # - shared/gh.md -# - shared/reporting.md # - shared/github-queries-mcp-script.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # - shared/otlp.md -# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md +# - shared/reporting.md +# - shared/reporting-otlp.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-copilot.lock.yml b/.github/workflows/smoke-copilot.lock.yml index 420a6cbdd7b..ca71862b1cc 100644 --- a/.github/workflows/smoke-copilot.lock.yml +++ b/.github/workflows/smoke-copilot.lock.yml @@ -31,12 +31,12 @@ # - shared/gh.md # - shared/reporting.md # - shared/github-queries-mcp-script.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # - shared/otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md # - shared/playwright-title-test.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-crush.lock.yml b/.github/workflows/smoke-crush.lock.yml index ff1a520d025..9e135e5de11 100644 --- a/.github/workflows/smoke-crush.lock.yml +++ b/.github/workflows/smoke-crush.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/crush.md # - shared/gh.md -# - shared/reporting.md # - shared/otlp.md -# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md +# - shared/reporting.md +# - shared/reporting-otlp.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/smoke-cursor.lock.yml b/.github/workflows/smoke-cursor.lock.yml index ea63eb27716..76b9767f870 100644 --- a/.github/workflows/smoke-cursor.lock.yml +++ b/.github/workflows/smoke-cursor.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/cursor.md # - shared/gh.md -# - shared/reporting.md # - shared/otlp.md -# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md +# - shared/reporting.md +# - shared/reporting-otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-deepseek-harness.lock.yml b/.github/workflows/smoke-deepseek-harness.lock.yml index 070345f7eae..26e17f3e1ab 100644 --- a/.github/workflows/smoke-deepseek-harness.lock.yml +++ b/.github/workflows/smoke-deepseek-harness.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/deepseek-harness.md # - shared/gh.md -# - shared/reporting.md # - shared/otlp.md -# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md +# - shared/reporting.md +# - shared/reporting-otlp.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/smoke-gemini.lock.yml b/.github/workflows/smoke-gemini.lock.yml index 15ae922ed66..a0cc993f2ce 100644 --- a/.github/workflows/smoke-gemini.lock.yml +++ b/.github/workflows/smoke-gemini.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/reporting.md # - shared/otlp.md -# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md # - shared/playwright-title-test.md +# - shared/reporting.md +# - shared/reporting-otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-goose.lock.yml b/.github/workflows/smoke-goose.lock.yml index b13a3e52361..91f72bf730f 100644 --- a/.github/workflows/smoke-goose.lock.yml +++ b/.github/workflows/smoke-goose.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/goose.md # - shared/gh.md -# - shared/reporting.md # - shared/otlp.md -# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md +# - shared/reporting.md +# - shared/reporting-otlp.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/smoke-kiro.lock.yml b/.github/workflows/smoke-kiro.lock.yml index 0f6386d8ce0..ec272c8ea77 100644 --- a/.github/workflows/smoke-kiro.lock.yml +++ b/.github/workflows/smoke-kiro.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/kiro.md # - shared/gh.md -# - shared/reporting.md # - shared/otlp.md -# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md +# - shared/reporting.md +# - shared/reporting-otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-opencode.lock.yml b/.github/workflows/smoke-opencode.lock.yml index 8fb659493fc..10d2796fae8 100644 --- a/.github/workflows/smoke-opencode.lock.yml +++ b/.github/workflows/smoke-opencode.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/opencode.md # - shared/gh.md -# - shared/reporting.md # - shared/otlp.md -# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md +# - shared/reporting.md +# - shared/reporting-otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-pi.lock.yml b/.github/workflows/smoke-pi.lock.yml index 873d13f1a93..571605b8de5 100644 --- a/.github/workflows/smoke-pi.lock.yml +++ b/.github/workflows/smoke-pi.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/gh.md -# - shared/reporting.md # - shared/otlp.md -# - shared/reporting-otlp.md # - shared/smoke-test-brevity.md +# - shared/reporting.md +# - shared/reporting-otlp.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/spec-extractor.lock.yml b/.github/workflows/spec-extractor.lock.yml index 38d402253bb..01b51171e1b 100644 --- a/.github/workflows/spec-extractor.lock.yml +++ b/.github/workflows/spec-extractor.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md +# - shared/otlp.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md -# - shared/otlp.md # # Secrets used: # - GH_AW_CI_TRIGGER_TOKEN diff --git a/.github/workflows/spec-librarian.lock.yml b/.github/workflows/spec-librarian.lock.yml index 26294875ffb..1cf9a8f6ac2 100644 --- a/.github/workflows/spec-librarian.lock.yml +++ b/.github/workflows/spec-librarian.lock.yml @@ -29,12 +29,12 @@ # Imports: # - shared/reporting.md # - shared/skip-if-issue-open.md +# - shared/otlp.md # - shared/activation-app.md # - shared/daily-issue-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md -# - shared/otlp.md # # Secrets used: # - GH_AW_AGENT_TOKEN diff --git a/.github/workflows/stale-repo-identifier.lock.yml b/.github/workflows/stale-repo-identifier.lock.yml index 63a9b8ff6a8..d8dc9593d8f 100644 --- a/.github/workflows/stale-repo-identifier.lock.yml +++ b/.github/workflows/stale-repo-identifier.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/mcp-pagination.md # - shared/github-guard-policy.md -# - shared/trending-charts-simple.md -# - shared/daily-audit-discussion.md # - ../skills/jqschema/SKILL.md # - shared/otlp.md # - shared/reporting.md +# - shared/trending-charts-simple.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # diff --git a/.github/workflows/terminal-stylist.lock.yml b/.github/workflows/terminal-stylist.lock.yml index 9a38d8e80c1..26e481d7bca 100644 --- a/.github/workflows/terminal-stylist.lock.yml +++ b/.github/workflows/terminal-stylist.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/daily-audit-discussion.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # - shared/reporting.md # - shared/otlp.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/typist.lock.yml b/.github/workflows/typist.lock.yml index c735546e844..e9af110c3a1 100644 --- a/.github/workflows/typist.lock.yml +++ b/.github/workflows/typist.lock.yml @@ -28,11 +28,11 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-discussion.md +# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md -# - shared/otlp.md -# - shared/daily-audit-base.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/ubuntu-image-analyzer.lock.yml b/.github/workflows/ubuntu-image-analyzer.lock.yml index edd13d986bf..880f97058d8 100644 --- a/.github/workflows/ubuntu-image-analyzer.lock.yml +++ b/.github/workflows/ubuntu-image-analyzer.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md +# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md -# - shared/otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/uk-ai-operational-resilience.lock.yml b/.github/workflows/uk-ai-operational-resilience.lock.yml index c3938ac911c..e8805e5461d 100644 --- a/.github/workflows/uk-ai-operational-resilience.lock.yml +++ b/.github/workflows/uk-ai-operational-resilience.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/mcp-pagination.md -# - shared/daily-audit-discussion.md # - shared/otlp.md # - shared/reporting.md +# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/unbloat-docs.lock.yml b/.github/workflows/unbloat-docs.lock.yml index d2650b4d792..fc7a15872ca 100644 --- a/.github/workflows/unbloat-docs.lock.yml +++ b/.github/workflows/unbloat-docs.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/activation-app.md # - shared/otlp.md # - shared/reporting.md +# - shared/activation-app.md # - shared/daily-pr-base.md # # Secrets used: diff --git a/.github/workflows/weekly-issue-summary.lock.yml b/.github/workflows/weekly-issue-summary.lock.yml index ffb5503e123..aba771757ba 100644 --- a/.github/workflows/weekly-issue-summary.lock.yml +++ b/.github/workflows/weekly-issue-summary.lock.yml @@ -28,12 +28,12 @@ # Resolved workflow manifest: # Imports: # - shared/github-guard-policy.md +# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/daily-audit-base.md # - shared/python-dataviz.md # - shared/trends.md -# - shared/otlp.md -# - shared/daily-audit-base.md # # Secrets used: # - CODEX_API_KEY