Skip to content

Commit 65bfd42

Browse files
Copilotpelikhan
andauthored
Start merge conflict resolution
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
2 parents ac1a67e + a0f95cf commit 65bfd42

307 files changed

Lines changed: 13732 additions & 3819 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

.changeset/patch-bump-awf-v0-27-31.md

Lines changed: 5 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

.github/aw/actions-lock.json

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -197,6 +197,11 @@
197197
"digest": "sha256:d0beee47dd38e2df577d15b9ddf763a2b771367326fecb02e1aa924bc395954a",
198198
"pinned_image": "ghcr.io/github/gh-aw-firewall/agent-act:0.27.30@sha256:d0beee47dd38e2df577d15b9ddf763a2b771367326fecb02e1aa924bc395954a"
199199
},
200+
"ghcr.io/github/gh-aw-firewall/agent-act:0.27.31": {
201+
"image": "ghcr.io/github/gh-aw-firewall/agent-act:0.27.31",
202+
"digest": "sha256:58fee05c1c54ba5ca1e7056b3aaea30281841d5899093002e2c650710c50540f",
203+
"pinned_image": "ghcr.io/github/gh-aw-firewall/agent-act:0.27.31@sha256:58fee05c1c54ba5ca1e7056b3aaea30281841d5899093002e2c650710c50540f"
204+
},
200205
"ghcr.io/github/gh-aw-firewall/agent:0.25.18": {
201206
"image": "ghcr.io/github/gh-aw-firewall/agent:0.25.18",
202207
"digest": "sha256:c77e8c26bab6c39e8568d8e2f8c17015944849a8cbcdfb4bd9725d8893725ca2",
@@ -297,6 +302,11 @@
297302
"digest": "sha256:3cc1e14efa9e52ed1fc29d72a0eabf02ff86b30c6af9685fa9ddd687caca6613",
298303
"pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.30@sha256:3cc1e14efa9e52ed1fc29d72a0eabf02ff86b30c6af9685fa9ddd687caca6613"
299304
},
305+
"ghcr.io/github/gh-aw-firewall/agent:0.27.31": {
306+
"image": "ghcr.io/github/gh-aw-firewall/agent:0.27.31",
307+
"digest": "sha256:84d861cb6da723ac10b7a00dddf778be681b8cd74b2091f18ce1d67fe4b3e7a1",
308+
"pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.31@sha256:84d861cb6da723ac10b7a00dddf778be681b8cd74b2091f18ce1d67fe4b3e7a1"
309+
},
300310
"ghcr.io/github/gh-aw-firewall/agent:0.27.4": {
301311
"image": "ghcr.io/github/gh-aw-firewall/agent:0.27.4",
302312
"digest": "sha256:b268ebf37df2428b19efcb383f001d65dc6a5ec10af43feb886d1a8477ab0e3a",
@@ -417,6 +427,11 @@
417427
"digest": "sha256:fdbd94bb668ed736a27c146633842db5c7e658dc7a0d6a0e6011e74e18132785",
418428
"pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.30@sha256:fdbd94bb668ed736a27c146633842db5c7e658dc7a0d6a0e6011e74e18132785"
419429
},
430+
"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.31": {
431+
"image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.31",
432+
"digest": "sha256:80d982fe7925c640d76cbbfbe94081d2d34f7657b7c37494d8d5488f5dae3c63",
433+
"pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.31@sha256:80d982fe7925c640d76cbbfbe94081d2d34f7657b7c37494d8d5488f5dae3c63"
434+
},
420435
"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.4": {
421436
"image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.4",
422437
"digest": "sha256:3ea0d12a2d124db8ed6e2d18aff040e30ab3568161f258a132fccdeede4198cd",
@@ -462,6 +477,11 @@
462477
"digest": "sha256:6ce8eb6ef9b959dd4bab4b005efba76f2dde0834a2716d18221965eb317ed2fa",
463478
"pinned_image": "ghcr.io/github/gh-aw-firewall/build-tools:0.27.30@sha256:6ce8eb6ef9b959dd4bab4b005efba76f2dde0834a2716d18221965eb317ed2fa"
464479
},
480+
"ghcr.io/github/gh-aw-firewall/build-tools:0.27.31": {
481+
"image": "ghcr.io/github/gh-aw-firewall/build-tools:0.27.31",
482+
"digest": "sha256:b10c0c125cb63fc0f039503a4594b40391be7991985e6e19aee63d068a84d7ad",
483+
"pinned_image": "ghcr.io/github/gh-aw-firewall/build-tools:0.27.31@sha256:b10c0c125cb63fc0f039503a4594b40391be7991985e6e19aee63d068a84d7ad"
484+
},
465485
"ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.28": {
466486
"image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.25.28",
467487
"digest": "sha256:fdf310e4678ce58d248c466b89399e9680a3003038fd19322c388559016aaac7",
@@ -547,6 +567,11 @@
547567
"digest": "sha256:959c876217038ac6f9c2047b591e819e5f1f726625a34490ccdcacaa71d83e4c",
548568
"pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.30@sha256:959c876217038ac6f9c2047b591e819e5f1f726625a34490ccdcacaa71d83e4c"
549569
},
570+
"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.31": {
571+
"image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.31",
572+
"digest": "sha256:7c63bc4e57d6eac1be996bb793a5a2d74d40b15a616003f4b6805a457046c673",
573+
"pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.31@sha256:7c63bc4e57d6eac1be996bb793a5a2d74d40b15a616003f4b6805a457046c673"
574+
},
550575
"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.4": {
551576
"image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.4",
552577
"digest": "sha256:72c378c029d2fad4684847ab44c329e526ac6b1a78cdf97656870ea11d201545",
@@ -667,6 +692,11 @@
667692
"digest": "sha256:eb74fca5309c7542df0f32aef41b92c728ecef7ac3b0cca9f9a6b97cc324d22a",
668693
"pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.30@sha256:eb74fca5309c7542df0f32aef41b92c728ecef7ac3b0cca9f9a6b97cc324d22a"
669694
},
695+
"ghcr.io/github/gh-aw-firewall/squid:0.27.31": {
696+
"image": "ghcr.io/github/gh-aw-firewall/squid:0.27.31",
697+
"digest": "sha256:c05a3f086946fab0833e078f46d35571080f187ca72f038958d45aa5cc150494",
698+
"pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.31@sha256:c05a3f086946fab0833e078f46d35571080f187ca72f038958d45aa5cc150494"
699+
},
670700
"ghcr.io/github/gh-aw-firewall/squid:0.27.4": {
671701
"image": "ghcr.io/github/gh-aw-firewall/squid:0.27.4",
672702
"digest": "sha256:87979038897e40caed22245b64d1daa796390d2dca289b99d3d1174c85740af8",

.github/aw/github-mcp-server.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -159,6 +159,8 @@ When the GitHub tool is configured, gh-aw injects a separate `<github-context>`
159159
| Tool | Purpose | Key Parameters |
160160
|------|---------|----------------|
161161
| `add_issue_comment` | Add a comment to an issue | `owner`, `repo`, `issue_number`, `body` |
162+
| `issue_dependency_read` | Read an issue's dependency relationships | `owner`, `repo`, `issue_number` |
163+
| `issue_dependency_write` | Add or remove issue dependencies | `owner`, `repo`, `issue_number` |
162164
| `issue_read` | Read issue details and comments | `owner`, `repo`, `issue_number` |
163165
| `issue_write` | Create or update an issue | `owner`, `repo`, `title`, `body`, `labels`, `assignees` |
164166
| `list_issue_types` | List available issue types for a repository | `owner`, `repo` |

.github/aw/syntax-agentic.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -344,6 +344,7 @@ description: Agentic workflow specific frontmatter fields for GitHub Agentic Wor
344344
```
345345

346346
- **`sandbox.agent.sudo`** (boolean) controls whether AWF runs in root mode. Default is `false`: AWF runs rootless in network-isolation egress mode (`--network-isolation`), with MCP sidecars attached as bridge containers on the internal `awf-net` network. Set `sudo: true` for the legacy root mode; in strict mode explicit `sudo: true` is an error (warning otherwise).
347+
- **`sandbox.agent.runtime`** (string) selects an extra-isolation container runtime for the agent: `gvisor` (runs under gVisor's `runsc` for kernel-level isolation) or `docker-sbx` (Docker sbx microVM with KVM hypervisor-level isolation; needs `DOCKER_PAT`/`DOCKER_USERNAME` secrets and a KVM-capable runner). Both require `sudo: true` and are incompatible with `runner.topology: arc-dind`.
347348
- **Strict mode**: `sandbox.agent` blocks without an explicit `id: awf` are rejected in strict mode. Any non-nil, non-disabled agent config without `id`/`type` defaults to AWF at runtime.
348349

349350
- **`tools:`** - Tool configuration for the coding agent (`github`, `agentic-workflows`, `edit`, `web-fetch`, `web-search`, `bash`, `playwright`, custom MCP server names, plus `timeout`/`startup-timeout`/`cli-proxy`). See [syntax-tools-imports.md](syntax-tools-imports.md#tool-configuration) for the full schema (GitHub `mode`/`toolsets`/integrity fields, bash allowlist decision rule, Playwright CLI mode).

.github/aw/syntax-tools-imports.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -85,6 +85,7 @@ The `tools:` field configures which tools the coding agent may use.
8585
- `blocked-users:` - Usernames whose content is unconditionally blocked (array or GitHub Actions expression); these users receive integrity below `none` and are always denied
8686
- `approval-labels:` - Label names that elevate a content item's integrity to `approved` when present (array or GitHub Actions expression); does not override `blocked-users`
8787
- `trusted-users:` - Usernames elevated to `approved` integrity regardless of `author_association` (array or GitHub Actions expression); takes precedence over `min-integrity` but not over `blocked-users`; requires `min-integrity` to be set
88+
- `private-to-public-flows:` - Opt out of MCP Gateway cross-visibility protections (which block private-repo data from reaching public sinks). `allow` disables `forcePublicRepos` and sink-visibility enforcement for all servers (**not compatible with strict mode**); an array of MCP server IDs (e.g. `[github, my-server]`) exempts only those servers from sink-visibility enforcement (strict-mode compatible, keeps `forcePublicRepos`). Security-sensitive — only use when private→public flows are intended.
8889
- `toolsets:` - Enable specific GitHub toolset groups (array only)
8990
- **Default toolsets** (when unspecified): `context`, `repos`, `issues`, `pull_requests` (excludes `users` as GitHub Actions tokens don't support user operations)
9091
- **Group aliases**: `default` (recommended action-friendly set), `action-friendly` (action-safe toolsets, excludes `users`), `all` (everything)

0 commit comments

Comments
 (0)