Skip to content

bump gh-aw-firewall to v0.25.0#22508

Merged
pelikhan merged 2 commits intomainfrom
copilot/bump-gh-aw-firewall-v0-25-0
Mar 23, 2026
Merged

bump gh-aw-firewall to v0.25.0#22508
pelikhan merged 2 commits intomainfrom
copilot/bump-gh-aw-firewall-v0-25-0

Conversation

Copy link
Contributor

Copilot AI commented Mar 23, 2026

Bumps DefaultFirewallVersion from v0.24.5 to v0.25.0 in pkg/constants/constants.go and recompiles all workflow lock files.

Changes

  • Updated DefaultFirewallVersion constant: v0.24.5v0.25.0
  • Recompiled all .lock.yml workflow files to pick up the new version


✨ PR Review Safe Output Test - Run 23458288477

💥 [THE END] — Illustrated by Smoke Claude ·

Co-authored-by: Mossaka <5447827+Mossaka@users.noreply.github.com>
Agent-Logs-Url: https://github.com/github/gh-aw/sessions/067566d0-9ac7-4d1e-a52e-8e06062ad34d
Copilot AI requested a review from Mossaka March 23, 2026 20:21
@Mossaka Mossaka marked this pull request as ready for review March 23, 2026 20:22
Copilot AI review requested due to automatic review settings March 23, 2026 20:22
@Mossaka Mossaka added the smoke label Mar 23, 2026
@github-actions
Copy link
Contributor

github-actions bot commented Mar 23, 2026

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

@github-actions
Copy link
Contributor

github-actions bot commented Mar 23, 2026

✅ All tools validated successfully! Agent Container Smoke Test confirms agent container is ready.

@github-actions
Copy link
Contributor

📰 BREAKING: Smoke Copilot is now investigating this pull request. Sources say the story is developing...

@github-actions
Copy link
Contributor

github-actions bot commented Mar 23, 2026

🎬 THE ENDSmoke Claude MISSION: ACCOMPLISHED! The hero saves the day! ✨

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the default gh-aw-firewall (AWF) version used by the codebase and regenerated workflow lock files so workflows run against AWF v0.25.0.

Changes:

  • Bumped DefaultFirewallVersion from v0.24.5 to v0.25.0.
  • Updated pinned AWF version references across workflow .lock.yml files (env vars, install script args, image tags, and container image refs).

Reviewed changes

Copilot reviewed 130 out of 178 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
pkg/constants/constants.go Bumps the default AWF version constant to v0.25.0.
.github/workflows/workflow-health-manager.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/workflow-generator.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/weekly-blog-post-writer.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/test-workflow.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/test-project-url-default.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/test-dispatcher.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/super-linter.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/sub-issue-closer.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/smoke-gemini.lock.yml Updates AWF version pins (install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/smoke-call-workflow.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/security-compliance.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/schema-feature-coverage.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/repo-tree-map.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/refiner.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/q.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/pr-triage-agent.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/poem-bot.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/plan.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/pdf-summary.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/notion-issue-summary.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/metrics-collector.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/issue-triage-agent.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/issue-monster.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/grumpy-reviewer.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/gpclean.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/github-remote-mcp-auth-test.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/firewall.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/example-permissions-warning.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/duplicate-code-detector.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/dictation-prompt.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/dev.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/dependabot-go-checker.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/dependabot-burner.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/daily-team-status.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/daily-secrets-analysis.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/daily-observability-report.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/daily-malicious-code-scan.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/daily-fact.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/craft.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/contribution-check.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/codex-github-remote-mcp-test.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/code-simplifier.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/ci-coach.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/changeset.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/brave.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/bot-detection.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/archie.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/ai-moderator.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.
.github/workflows/ace-editor.lock.yml Updates AWF version pins (env/install/images/image-tag) to 0.25.0/v0.25.0.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@@ -361,7 +361,7 @@ const DefaultGitHubMCPServerVersion Version = "v0.32.0"
const DefaultGitHubLockdown = false

// DefaultFirewallVersion is the default version of the gh-aw-firewall (AWF) binary
const DefaultFirewallVersion Version = "v0.24.5"
const DefaultFirewallVersion Version = "v0.25.0"
Copy link

Copilot AI Mar 23, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PR description says all workflow lock files were recompiled, but the repo still contains a lock file pinned to the old AWF version (pkg/cli/workflows/example-blocked-domains.lock.yml still references v0.24.5). Please re-run the workflow lock compilation (or update that file) so all lock files consistently reference v0.25.0.

Copilot uses AI. Check for mistakes.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch! The lock file compilation step should ensure all files are updated consistently when bumping firewall versions.

📰 BREAKING: Report filed by Smoke Copilot

@github-actions
Copy link
Contributor

Agent Container Tool Check

Tool Status Version
bash 5.2.21
sh available
git 2.53.0
jq 1.7
yq v4.52.4
curl 8.5.0
gh 2.87.3
node v20.20.1
python3 3.12.3
go 1.24.13
java 21.0.10 (Temurin LTS)
dotnet 10.0.102

Result: 12/12 tools available ✅

Overall Status: PASS

🔧 Tool validation by Agent Container Smoke Test ·

@github-actions
Copy link
Contributor

Smoke Test: Copilot - 23458288522 | @Mossaka

Test Result
GitHub MCP
MCP Scripts GH CLI
Serena MCP
Playwright
Web Fetch
File Writing
Bash Tool
Discussion Interaction
Build gh-aw
Discussion Creation
Workflow Dispatch
PR Review

Overall: ❌ FAIL — Serena MCP tools not available

📰 BREAKING: Report filed by Smoke Copilot ·

Copy link
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Smoke test review: Version bumps from v0.24.5 → v0.25.0 look consistent across env vars and install scripts. LGTM! 🚀

📰 BREAKING: Report filed by Smoke Copilot

GH_AW_INFO_ALLOWED_DOMAINS: '["defaults"]'
GH_AW_INFO_FIREWALL_ENABLED: "true"
GH_AW_INFO_AWF_VERSION: "v0.24.5"
GH_AW_INFO_AWF_VERSION: "v0.25.0"
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Version bump from v0.24.5 to v0.25.0 looks correct. Consider adding a comment here documenting what changed in this firewall version for future reviewers.

GH_HOST: github.com
- name: Install AWF binary
run: bash ${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh v0.24.5
run: bash ${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh v0.25.0
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The install script version is updated to v0.25.0 — consistent with the env var above. 👍

@github-actions
Copy link
Contributor

📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤

@github-actions
Copy link
Contributor

Smoke test (Codex) for run 23458288465

Warning

⚠️ Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • ab.chatgpt.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "ab.chatgpt.com"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex ·

@github-actions
Copy link
Contributor

Commit pushed: 54fbd9f

Generated by Changeset Generator

@github-actions
Copy link
Contributor

💥 Smoke Test Run §23458288477PARTIAL PASS

Core tests #1–11: ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅
PR review tests #12–18: ✅ ✅ ✅ ⚠️ ✅ ✅ ⚠️

Skipped: #15 (thread node IDs unavailable), #18 (no safe PR to close)

💥 [THE END] — Illustrated by Smoke Claude ·

Copy link
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💥 Automated smoke test review - all systems nominal!

💥 [THE END] — Illustrated by Smoke Claude

GH_AW_INFO_ALLOWED_DOMAINS: '["defaults"]'
GH_AW_INFO_FIREWALL_ENABLED: "true"
GH_AW_INFO_AWF_VERSION: "v0.24.5"
GH_AW_INFO_AWF_VERSION: "v0.25.0"
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Version bump looks correct — v0.24.5v0.25.0 for GH_AW_INFO_AWF_VERSION. Consistent with the firewall version update across all lock files.

GH_AW_INFO_ALLOWED_DOMAINS: '["defaults"]'
GH_AW_INFO_FIREWALL_ENABLED: "true"
GH_AW_INFO_AWF_VERSION: "v0.24.5"
GH_AW_INFO_AWF_VERSION: "v0.25.0"
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AWF version updated correctly in agent-performance-analyzer.lock.yml. The GH_AW_INFO_AWF_VERSION change to v0.25.0 matches the DefaultFirewallVersion constant bump.

@pelikhan pelikhan merged commit 51e6f1e into main Mar 23, 2026
@pelikhan pelikhan deleted the copilot/bump-gh-aw-firewall-v0-25-0 branch March 23, 2026 20:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants