From 3f180e18c4397babba5d7e60e838f4a156b1531f Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 2 Sep 2026 00:11:25 +0000 Subject: [PATCH 1/2] Plan engine selection guidance update Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --- .github/workflows/agent-job-health.lock.yml | 4 +- .../workflows/api-consumption-report.lock.yml | 8 +-- .github/workflows/archie.lock.yml | 2 +- .../workflows/architecture-guardian.lock.yml | 2 +- .github/workflows/audit-workflows.lock.yml | 8 +-- .github/workflows/blog-auditor.lock.yml | 2 +- .../breaking-change-checker.lock.yml | 2 +- .github/workflows/ci-coach.lock.yml | 4 +- .../claude-code-user-docs-review.lock.yml | 2 +- .github/workflows/cloclo.lock.yml | 4 +- .../workflows/code-scanning-fixer.lock.yml | 2 +- .github/workflows/code-simplifier.lock.yml | 2 +- .../workflows/copilot-agent-analysis.lock.yml | 6 +- .../copilot-pr-merged-report.lock.yml | 6 +- .../copilot-pr-nlp-analysis.lock.yml | 22 +++---- .../copilot-pr-prompt-analysis.lock.yml | 6 +- .../copilot-session-insights.lock.yml | 6 +- .../daily-architecture-diagram.lock.yml | 2 +- .../workflows/daily-cli-performance.lock.yml | 4 +- .../workflows/daily-cli-tools-tester.lock.yml | 2 +- .github/workflows/daily-code-metrics.lock.yml | 4 +- .../workflows/daily-compiler-quality.lock.yml | 4 +- ...ly-compiler-threat-spec-optimizer.lock.yml | 2 +- .github/workflows/daily-doc-healer.lock.yml | 2 +- .../daily-experiment-report.lock.yml | 2 +- .github/workflows/daily-file-diet.lock.yml | 4 +- .../daily-formal-spec-verifier.lock.yml | 2 +- .../workflows/daily-function-namer.lock.yml | 4 +- .../workflows/daily-geo-optimizer.lock.yml | 2 +- .../daily-graft-intelligence.lock.yml | 6 +- .../workflows/daily-issues-report.lock.yml | 66 +++++++++---------- .../daily-malicious-code-scan.lock.yml | 2 +- .../daily-mcp-concurrency-analysis.lock.yml | 2 +- .../daily-multi-device-docs-tester.lock.yml | 2 +- .github/workflows/daily-news.lock.yml | 6 +- .../daily-observability-report.lock.yml | 2 +- .../daily-performance-summary.lock.yml | 4 +- .github/workflows/daily-regulatory.lock.yml | 2 +- .../daily-reliability-review.lock.yml | 2 +- .../daily-rendering-scripts-verifier.lock.yml | 2 +- .../workflows/daily-repo-chronicle.lock.yml | 6 +- .../daily-safe-output-integrator.lock.yml | 2 +- .../daily-safe-output-optimizer.lock.yml | 2 +- .../daily-safe-outputs-conformance.lock.yml | 2 +- .../workflows/daily-secrets-analysis.lock.yml | 2 +- .../daily-security-observability.lock.yml | 20 +++--- .../daily-security-red-team.lock.yml | 2 +- .../daily-spdd-spec-planner.lock.yml | 2 +- .../daily-team-evolution-insights.lock.yml | 2 +- .../daily-testify-uber-super-expert.lock.yml | 4 +- .../daily-token-consumption-report.lock.yml | 2 +- .github/workflows/dead-code-remover.lock.yml | 2 +- .github/workflows/delight.lock.yml | 2 +- .github/workflows/dependabot-burner.lock.yml | 2 +- .../detection-analysis-report.lock.yml | 12 ++-- .../developer-docs-consolidator.lock.yml | 4 +- .github/workflows/docs-noob-tester.lock.yml | 4 +- .../duplicate-code-detector.lock.yml | 4 +- .github/workflows/eslint-refiner.lock.yml | 2 +- .../example-workflow-analyzer.lock.yml | 2 +- .../github-mcp-structural-analysis.lock.yml | 4 +- .../github-mcp-tools-report.lock.yml | 2 +- .../github-remote-mcp-auth-test.lock.yml | 2 +- .../workflows/glossary-maintainer.lock.yml | 4 +- .github/workflows/go-fan.lock.yml | 2 +- .github/workflows/grumpy-reviewer.lock.yml | 2 +- .../impeccable-skills-reviewer.lock.yml | 6 +- .github/workflows/linter-miner.lock.yml | 4 +- .github/workflows/lockfile-stats.lock.yml | 2 +- .../mattpocock-skills-reviewer.lock.yml | 4 +- .github/workflows/mcp-inspector.lock.yml | 8 +-- .github/workflows/ponytail-reviewer.lock.yml | 4 +- .github/workflows/portfolio-analyst.lock.yml | 2 +- .../pr-code-quality-reviewer.lock.yml | 4 +- .../workflows/pr-nitpick-reviewer.lock.yml | 4 +- .github/workflows/pr-triage-agent.lock.yml | 2 +- .../prompt-clustering-analysis.lock.yml | 30 ++++----- .github/workflows/purelock.lock.yml | 4 +- .github/workflows/python-data-charts.lock.yml | 4 +- .../workflows/refactoring-cadence.lock.yml | 2 +- .github/workflows/refiner.lock.yml | 4 +- .../workflows/repo-audit-analyzer.lock.yml | 2 +- .../repository-quality-improver.lock.yml | 4 +- .github/workflows/safe-output-health.lock.yml | 4 +- .../schema-consistency-checker.lock.yml | 2 +- .github/workflows/security-review.lock.yml | 4 +- .../semantic-function-refactor.lock.yml | 4 +- .github/workflows/sergo.lock.yml | 6 +- .github/workflows/skillet.lock.yml | 2 +- .../workflows/slide-deck-maintainer.lock.yml | 2 +- .github/workflows/smoke-codex.lock.yml | 8 +-- .../smoke-copilot-aoai-apikey.lock.yml | 4 +- .../smoke-copilot-aoai-entra.lock.yml | 14 ++-- .github/workflows/smoke-copilot-arm.lock.yml | 8 +-- .github/workflows/smoke-copilot.lock.yml | 4 +- .github/workflows/smoke-crush.lock.yml | 4 +- .github/workflows/smoke-cursor.lock.yml | 4 +- .../workflows/smoke-deepseek-harness.lock.yml | 4 +- .github/workflows/smoke-gemini.lock.yml | 4 +- .github/workflows/smoke-goose.lock.yml | 4 +- .github/workflows/smoke-kiro.lock.yml | 4 +- .github/workflows/smoke-opencode.lock.yml | 4 +- .github/workflows/smoke-pi.lock.yml | 4 +- .github/workflows/spec-extractor.lock.yml | 2 +- .github/workflows/spec-librarian.lock.yml | 2 +- .../workflows/stale-repo-identifier.lock.yml | 4 +- .github/workflows/terminal-stylist.lock.yml | 6 +- .github/workflows/typist.lock.yml | 4 +- .../workflows/ubuntu-image-analyzer.lock.yml | 2 +- .../uk-ai-operational-resilience.lock.yml | 2 +- .github/workflows/unbloat-docs.lock.yml | 2 +- .../workflows/weekly-issue-summary.lock.yml | 4 +- 112 files changed, 263 insertions(+), 263 deletions(-) diff --git a/.github/workflows/agent-job-health.lock.yml b/.github/workflows/agent-job-health.lock.yml index 1d6193c8624..3aa5b07ba6a 100644 --- a/.github/workflows/agent-job-health.lock.yml +++ b/.github/workflows/agent-job-health.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/aw-logs-24h-fetch.md -# - ../skills/jqschema/SKILL.md # - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md # - shared/daily-audit-base.md +# - shared/aw-logs-24h-fetch.md +# - ../skills/jqschema/SKILL.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/api-consumption-report.lock.yml b/.github/workflows/api-consumption-report.lock.yml index 84542fbd45e..d473f6ad01b 100644 --- a/.github/workflows/api-consumption-report.lock.yml +++ b/.github/workflows/api-consumption-report.lock.yml @@ -28,17 +28,17 @@ # Resolved workflow manifest: # Imports: # - shared/cache-memory-trending.md +# - shared/trending-charts-simple.md +# - shared/daily-audit-discussion.md # - ../skills/jqschema/SKILL.md # - shared/reporting.md # - shared/otlp.md -# - shared/trending-charts-simple.md +# - shared/daily-audit-base.md +# - shared/daily-audit-charts.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md # - shared/graders.md -# - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md -# - shared/daily-audit-charts.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/archie.lock.yml b/.github/workflows/archie.lock.yml index aa9dd6ddad5..697739bb37d 100644 --- a/.github/workflows/archie.lock.yml +++ b/.github/workflows/archie.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/architecture-guardian.lock.yml b/.github/workflows/architecture-guardian.lock.yml index 5b67cb2a06b..2cc2116a6b4 100644 --- a/.github/workflows/architecture-guardian.lock.yml +++ b/.github/workflows/architecture-guardian.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md +# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/audit-workflows.lock.yml b/.github/workflows/audit-workflows.lock.yml index 5acdb9fc04e..f39051185d0 100644 --- a/.github/workflows/audit-workflows.lock.yml +++ b/.github/workflows/audit-workflows.lock.yml @@ -27,19 +27,19 @@ # # Resolved workflow manifest: # Imports: +# - shared/trending-charts-simple.md +# - shared/daily-audit-discussion.md # - shared/repo-memory-standard.md # - ../skills/jqschema/SKILL.md # - shared/reporting.md # - shared/otlp.md +# - shared/daily-audit-base.md +# - shared/daily-audit-charts.md # - shared/default-ai-credits-pricing.md -# - shared/trending-charts-simple.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md # - shared/graders.md -# - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md -# - shared/daily-audit-charts.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/blog-auditor.lock.yml b/.github/workflows/blog-auditor.lock.yml index 851446197db..c58b7f62919 100644 --- a/.github/workflows/blog-auditor.lock.yml +++ b/.github/workflows/blog-auditor.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md diff --git a/.github/workflows/breaking-change-checker.lock.yml b/.github/workflows/breaking-change-checker.lock.yml index 49cbe967dd8..621f1bf7f51 100644 --- a/.github/workflows/breaking-change-checker.lock.yml +++ b/.github/workflows/breaking-change-checker.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md +# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/ci-coach.lock.yml b/.github/workflows/ci-coach.lock.yml index b738303a0a6..010b188539e 100644 --- a/.github/workflows/ci-coach.lock.yml +++ b/.github/workflows/ci-coach.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: +# - ../skills/jqschema/SKILL.md +# - shared/ci-data-analysis.md # - shared/ci-optimization-strategies.md # - shared/reporting.md # - shared/otlp.md -# - ../skills/jqschema/SKILL.md -# - shared/ci-data-analysis.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/claude-code-user-docs-review.lock.yml b/.github/workflows/claude-code-user-docs-review.lock.yml index a45b4100cfd..88bd1291338 100644 --- a/.github/workflows/claude-code-user-docs-review.lock.yml +++ b/.github/workflows/claude-code-user-docs-review.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md diff --git a/.github/workflows/cloclo.lock.yml b/.github/workflows/cloclo.lock.yml index cb5546ceb58..f04848a5049 100644 --- a/.github/workflows/cloclo.lock.yml +++ b/.github/workflows/cloclo.lock.yml @@ -27,10 +27,10 @@ # Resolved workflow manifest: # Imports: # - ../skills/jqschema/SKILL.md -# - shared/reporting.md -# - shared/otlp.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/reporting.md +# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/code-scanning-fixer.lock.yml b/.github/workflows/code-scanning-fixer.lock.yml index 2923ab916cf..887906c6cd5 100644 --- a/.github/workflows/code-scanning-fixer.lock.yml +++ b/.github/workflows/code-scanning-fixer.lock.yml @@ -30,10 +30,10 @@ # - shared/mcp-pagination.md # - shared/skip-if-issue-open.md # - shared/security-analysis-base.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md +# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/code-simplifier.lock.yml b/.github/workflows/code-simplifier.lock.yml index a88dc8af2f6..6a17975d7b1 100644 --- a/.github/workflows/code-simplifier.lock.yml +++ b/.github/workflows/code-simplifier.lock.yml @@ -29,10 +29,10 @@ # Imports: # - shared/mcp-pagination.md # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md +# - shared/otlp.md # - shared/graders/state-revisit-probability-rep.md # - shared/graders/recurrence-determinism.md # - shared/graders/recurrence-laminarity.md diff --git a/.github/workflows/copilot-agent-analysis.lock.yml b/.github/workflows/copilot-agent-analysis.lock.yml index 0f447572765..4f88e6cd95a 100644 --- a/.github/workflows/copilot-agent-analysis.lock.yml +++ b/.github/workflows/copilot-agent-analysis.lock.yml @@ -27,13 +27,13 @@ # # Resolved workflow manifest: # Imports: -# - shared/repo-memory-standard.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/daily-audit-base.md +# - shared/repo-memory-standard.md # - shared/copilot-pr-data-fetch.md # - shared/copilot-pr-analysis-base.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/copilot-pr-merged-report.lock.yml b/.github/workflows/copilot-pr-merged-report.lock.yml index 483fb7aee8d..9cada2408c0 100644 --- a/.github/workflows/copilot-pr-merged-report.lock.yml +++ b/.github/workflows/copilot-pr-merged-report.lock.yml @@ -28,12 +28,12 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md -# - shared/gh.md -# - shared/otlp.md # - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md +# - shared/gh.md # - shared/copilot-pr-data-fetch.md # - shared/copilot-pr-analysis-base.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/copilot-pr-nlp-analysis.lock.yml b/.github/workflows/copilot-pr-nlp-analysis.lock.yml index 599ab2e9b3c..ab3d83f3dd2 100644 --- a/.github/workflows/copilot-pr-nlp-analysis.lock.yml +++ b/.github/workflows/copilot-pr-nlp-analysis.lock.yml @@ -27,15 +27,15 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md # - shared/repo-memory-standard.md +# - shared/copilot-pr-data-fetch.md # - shared/python-dataviz.md # - shared/python-nlp.md # - shared/reporting.md +# - shared/copilot-pr-analysis-base.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md -# - shared/copilot-pr-data-fetch.md -# - shared/copilot-pr-analysis-base.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN @@ -541,6 +541,14 @@ jobs: MEMORY_DIR: /tmp/gh-aw/repo-memory/default CREATE_ORPHAN: true run: bash "${RUNNER_TEMP}/gh-aw/actions/clone_repo_memory_branch.sh" + - name: Install gh CLI + run: | + bash "${RUNNER_TEMP}/gh-aw/actions/install_gh_cli.sh" + - env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + name: Fetch Copilot PR data + run: "# Create output directories\nmkdir -p /tmp/gh-aw/agent/pr-data\nmkdir -p /tmp/gh-aw/cache-memory\n\n# Cache files use stable names so restored caches from previous runs are reusable\n# regardless of the date they were written on. Freshness is decided by file age.\nCACHE_DIR=\"/tmp/gh-aw/cache-memory\"\nCACHE_FILE=\"$CACHE_DIR/copilot-prs-latest.json\"\nCACHE_SCHEMA_FILE=\"$CACHE_DIR/copilot-prs-latest-schema.json\"\nCACHE_MAX_AGE_SECONDS=\"${CACHE_MAX_AGE_SECONDS:-21600}\"\n\n# Returns success when the file exists, is non-empty and younger than the max age.\ncache_is_fresh() {\n cache_path=\"$1\"\n [ -s \"$cache_path\" ] || return 1\n cache_mtime=$(date -r \"$cache_path\" '+%s' 2>/dev/null) || return 1\n [ -n \"$cache_mtime\" ] || return 1\n now=$(date '+%s')\n [ \"$((now - cache_mtime))\" -lt \"$CACHE_MAX_AGE_SECONDS\" ]\n}\n\n# Check if restored cache data is still fresh enough to reuse\nif cache_is_fresh \"$CACHE_FILE\"; then\n CACHE_AGE_MINUTES=$(( ( $(date '+%s') - $(date -r \"$CACHE_FILE\" '+%s') ) / 60 ))\n echo \"✓ Found cached PR data (${CACHE_AGE_MINUTES} minutes old)\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n \n # Regenerate schema if missing\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n \n echo \"Using cached data written ${CACHE_AGE_MINUTES} minutes ago\"\n echo \"Total PRs in cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nelse\n echo \"⬇ Downloading fresh PR data...\"\n \n # Calculate date 30 days ago\n DATE_30_DAYS_AGO=$(date -d '30 days ago' '+%Y-%m-%d' 2>/dev/null || date -v-30d '+%Y-%m-%d')\n\n # Search for PRs from copilot/* branches in the last 30 days using gh CLI\n # Using branch prefix search (head:copilot/) instead of author for reliability\n echo \"Fetching Copilot PRs from the last 30 days...\"\n FETCH_TMP=\"${RUNNER_TEMP:-/tmp}/copilot-prs-fetch.json\"\n rm -f \"$FETCH_TMP\"\n FETCH_OK=true\n gh pr list --repo \"$GITHUB_REPOSITORY\" \\\n --search \"head:copilot/ created:>=${DATE_30_DAYS_AGO}\" \\\n --state all \\\n --json number,title,author,headRefName,createdAt,state,url,body,labels,updatedAt,closedAt,mergedAt \\\n --limit 1000 \\\n > \"$FETCH_TMP\" || FETCH_OK=false\n\n if [ \"$FETCH_OK\" != \"true\" ] || ! jq -e 'type == \"array\"' \"$FETCH_TMP\" >/dev/null 2>&1; then\n # Transient GitHub API failures (e.g. 503) must not fail the whole run when\n # stale cached data is still available; fall back to it instead.\n if [ -s \"$CACHE_FILE\" ]; then\n echo \"::warning::Failed to fetch Copilot PR data; falling back to stale cached data\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n echo \"Total PRs in stale cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\n echo \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\n echo \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n exit 0\n fi\n echo \"::error::Failed to fetch Copilot PR data and no cached data is available\"\n exit 1\n fi\n\n cp \"$FETCH_TMP\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n rm -f \"$FETCH_TMP\"\n\n # Generate schema for reference\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n\n # Store in cache under stable names so future runs can reuse it on any date\n cp /tmp/gh-aw/agent/pr-data/copilot-prs.json \"$CACHE_FILE\"\n cp /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json \"$CACHE_SCHEMA_FILE\"\n\n # Drop legacy date-keyed cache entries so the cache does not grow unbounded\n rm -f \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9].json \\\n \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]-schema.json 2>/dev/null || true\n\n echo \"✓ PR data saved to cache: $(basename \"$CACHE_FILE\")\"\n echo \"Total PRs found: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nfi\n\n# Always ensure data is available at expected locations for backward compatibility\necho \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\necho \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n" - name: Setup Python environment run: "# Create working directory for Python scripts\nmkdir -p /tmp/gh-aw/python\nmkdir -p /tmp/gh-aw/python/data\nmkdir -p /tmp/gh-aw/python/charts\nmkdir -p /tmp/gh-aw/python/artifacts\n\necho \"Python environment setup complete\"\necho \"Working directory: /tmp/gh-aw/python\"\necho \"Data directory: /tmp/gh-aw/python/data\"\necho \"Charts directory: /tmp/gh-aw/python/charts\"\necho \"Artifacts directory: /tmp/gh-aw/python/artifacts\"\n" - env: @@ -561,14 +569,6 @@ jobs: UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python name: Setup Python NLP environment run: "mkdir -p /tmp/gh-aw/python/{data,charts,artifacts}\n# Create a virtual environment for proper package isolation (avoids --break-system-packages)\n# Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/)\n# Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC).\n# This must match shared/python-dataviz.md so either import can create the shared environment first.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/pip install --quiet nltk scikit-learn textblob wordcloud\n\n# Download required NLTK corpora\n/tmp/gh-aw/python/venv/bin/python3 -c \"\nimport nltk\nfor corpus in ['punkt_tab', 'stopwords', 'vader_lexicon', 'averaged_perceptron_tagger_eng']:\n nltk.download(corpus, quiet=True)\nprint('NLTK corpora ready')\n\"\n\n/tmp/gh-aw/python/venv/bin/python3 -c \"import sklearn; print(f'scikit-learn {sklearn.__version__}')\"\n" - - name: Install gh CLI - run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_gh_cli.sh" - - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Fetch Copilot PR data - run: "# Create output directories\nmkdir -p /tmp/gh-aw/agent/pr-data\nmkdir -p /tmp/gh-aw/cache-memory\n\n# Cache files use stable names so restored caches from previous runs are reusable\n# regardless of the date they were written on. Freshness is decided by file age.\nCACHE_DIR=\"/tmp/gh-aw/cache-memory\"\nCACHE_FILE=\"$CACHE_DIR/copilot-prs-latest.json\"\nCACHE_SCHEMA_FILE=\"$CACHE_DIR/copilot-prs-latest-schema.json\"\nCACHE_MAX_AGE_SECONDS=\"${CACHE_MAX_AGE_SECONDS:-21600}\"\n\n# Returns success when the file exists, is non-empty and younger than the max age.\ncache_is_fresh() {\n cache_path=\"$1\"\n [ -s \"$cache_path\" ] || return 1\n cache_mtime=$(date -r \"$cache_path\" '+%s' 2>/dev/null) || return 1\n [ -n \"$cache_mtime\" ] || return 1\n now=$(date '+%s')\n [ \"$((now - cache_mtime))\" -lt \"$CACHE_MAX_AGE_SECONDS\" ]\n}\n\n# Check if restored cache data is still fresh enough to reuse\nif cache_is_fresh \"$CACHE_FILE\"; then\n CACHE_AGE_MINUTES=$(( ( $(date '+%s') - $(date -r \"$CACHE_FILE\" '+%s') ) / 60 ))\n echo \"✓ Found cached PR data (${CACHE_AGE_MINUTES} minutes old)\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n \n # Regenerate schema if missing\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n \n echo \"Using cached data written ${CACHE_AGE_MINUTES} minutes ago\"\n echo \"Total PRs in cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nelse\n echo \"⬇ Downloading fresh PR data...\"\n \n # Calculate date 30 days ago\n DATE_30_DAYS_AGO=$(date -d '30 days ago' '+%Y-%m-%d' 2>/dev/null || date -v-30d '+%Y-%m-%d')\n\n # Search for PRs from copilot/* branches in the last 30 days using gh CLI\n # Using branch prefix search (head:copilot/) instead of author for reliability\n echo \"Fetching Copilot PRs from the last 30 days...\"\n FETCH_TMP=\"${RUNNER_TEMP:-/tmp}/copilot-prs-fetch.json\"\n rm -f \"$FETCH_TMP\"\n FETCH_OK=true\n gh pr list --repo \"$GITHUB_REPOSITORY\" \\\n --search \"head:copilot/ created:>=${DATE_30_DAYS_AGO}\" \\\n --state all \\\n --json number,title,author,headRefName,createdAt,state,url,body,labels,updatedAt,closedAt,mergedAt \\\n --limit 1000 \\\n > \"$FETCH_TMP\" || FETCH_OK=false\n\n if [ \"$FETCH_OK\" != \"true\" ] || ! jq -e 'type == \"array\"' \"$FETCH_TMP\" >/dev/null 2>&1; then\n # Transient GitHub API failures (e.g. 503) must not fail the whole run when\n # stale cached data is still available; fall back to it instead.\n if [ -s \"$CACHE_FILE\" ]; then\n echo \"::warning::Failed to fetch Copilot PR data; falling back to stale cached data\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n echo \"Total PRs in stale cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\n echo \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\n echo \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n exit 0\n fi\n echo \"::error::Failed to fetch Copilot PR data and no cached data is available\"\n exit 1\n fi\n\n cp \"$FETCH_TMP\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n rm -f \"$FETCH_TMP\"\n\n # Generate schema for reference\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n\n # Store in cache under stable names so future runs can reuse it on any date\n cp /tmp/gh-aw/agent/pr-data/copilot-prs.json \"$CACHE_FILE\"\n cp /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json \"$CACHE_SCHEMA_FILE\"\n\n # Drop legacy date-keyed cache entries so the cache does not grow unbounded\n rm -f \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9].json \\\n \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]-schema.json 2>/dev/null || true\n\n echo \"✓ PR data saved to cache: $(basename \"$CACHE_FILE\")\"\n echo \"Total PRs found: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nfi\n\n# Always ensure data is available at expected locations for backward compatibility\necho \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\necho \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/copilot-pr-prompt-analysis.lock.yml b/.github/workflows/copilot-pr-prompt-analysis.lock.yml index 70dada575a6..95de1212f6c 100644 --- a/.github/workflows/copilot-pr-prompt-analysis.lock.yml +++ b/.github/workflows/copilot-pr-prompt-analysis.lock.yml @@ -27,13 +27,13 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md # - shared/repo-memory-standard.md +# - shared/copilot-pr-data-fetch.md # - shared/reporting.md +# - shared/copilot-pr-analysis-base.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md -# - shared/copilot-pr-data-fetch.md -# - shared/copilot-pr-analysis-base.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/copilot-session-insights.lock.yml b/.github/workflows/copilot-session-insights.lock.yml index b6302bf7540..7ff426e1764 100644 --- a/.github/workflows/copilot-session-insights.lock.yml +++ b/.github/workflows/copilot-session-insights.lock.yml @@ -28,16 +28,16 @@ # Resolved workflow manifest: # Imports: # - shared/mcp-pagination.md +# - shared/daily-audit-discussion.md # - shared/repo-memory-standard.md # - ../skills/jqschema/SKILL.md # - shared/copilot-session-data-fetch.md +# - shared/python-dataviz.md +# - shared/session-analysis-charts.md # - shared/session-analysis-strategies.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md -# - shared/python-dataviz.md -# - shared/session-analysis-charts.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/daily-architecture-diagram.lock.yml b/.github/workflows/daily-architecture-diagram.lock.yml index 77040434559..f6594731b82 100644 --- a/.github/workflows/daily-architecture-diagram.lock.yml +++ b/.github/workflows/daily-architecture-diagram.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-cli-performance.lock.yml b/.github/workflows/daily-cli-performance.lock.yml index 63fe97aff14..6c51ac652a9 100644 --- a/.github/workflows/daily-cli-performance.lock.yml +++ b/.github/workflows/daily-cli-performance.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/mcp-pagination.md -# - shared/go-make.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/go-make.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-cli-tools-tester.lock.yml b/.github/workflows/daily-cli-tools-tester.lock.yml index f32a8c6682e..36351c15d14 100644 --- a/.github/workflows/daily-cli-tools-tester.lock.yml +++ b/.github/workflows/daily-cli-tools-tester.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-code-metrics.lock.yml b/.github/workflows/daily-code-metrics.lock.yml index b91bda9c45d..c06d3b8816b 100644 --- a/.github/workflows/daily-code-metrics.lock.yml +++ b/.github/workflows/daily-code-metrics.lock.yml @@ -28,12 +28,12 @@ # Resolved workflow manifest: # Imports: # - shared/crush.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/daily-audit-base.md # - shared/python-dataviz.md # - shared/trends.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - DOCKER_PAT diff --git a/.github/workflows/daily-compiler-quality.lock.yml b/.github/workflows/daily-compiler-quality.lock.yml index 868c1fc59a9..f3319009d5e 100644 --- a/.github/workflows/daily-compiler-quality.lock.yml +++ b/.github/workflows/daily-compiler-quality.lock.yml @@ -28,12 +28,12 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - DOCKER_PAT diff --git a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml index fcef34eac6b..7d1582c9078 100644 --- a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml +++ b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-doc-healer.lock.yml b/.github/workflows/daily-doc-healer.lock.yml index 7c89a9e09a1..337ce0a86ba 100644 --- a/.github/workflows/daily-doc-healer.lock.yml +++ b/.github/workflows/daily-doc-healer.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-experiment-report.lock.yml b/.github/workflows/daily-experiment-report.lock.yml index f5b9f656895..310d4c234c3 100644 --- a/.github/workflows/daily-experiment-report.lock.yml +++ b/.github/workflows/daily-experiment-report.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/trending-charts-simple.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # diff --git a/.github/workflows/daily-file-diet.lock.yml b/.github/workflows/daily-file-diet.lock.yml index 113e004e1ef..1325a4246c6 100644 --- a/.github/workflows/daily-file-diet.lock.yml +++ b/.github/workflows/daily-file-diet.lock.yml @@ -28,14 +28,14 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md -# - shared/safe-output-app.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md +# - shared/safe-output-app.md +# - shared/otlp.md # # Secrets used: # - DOCKER_PAT diff --git a/.github/workflows/daily-formal-spec-verifier.lock.yml b/.github/workflows/daily-formal-spec-verifier.lock.yml index f3430761a78..234530946cc 100644 --- a/.github/workflows/daily-formal-spec-verifier.lock.yml +++ b/.github/workflows/daily-formal-spec-verifier.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md +# - shared/otlp.md # # Secrets used: # - GH_AW_AGENT_TOKEN diff --git a/.github/workflows/daily-function-namer.lock.yml b/.github/workflows/daily-function-namer.lock.yml index c129a29b95a..976b1053481 100644 --- a/.github/workflows/daily-function-namer.lock.yml +++ b/.github/workflows/daily-function-namer.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/daily-geo-optimizer.lock.yml b/.github/workflows/daily-geo-optimizer.lock.yml index f203caa8260..122c9e0ca02 100644 --- a/.github/workflows/daily-geo-optimizer.lock.yml +++ b/.github/workflows/daily-geo-optimizer.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-graft-intelligence.lock.yml b/.github/workflows/daily-graft-intelligence.lock.yml index d3abd6c8d56..752ba70ef4a 100644 --- a/.github/workflows/daily-graft-intelligence.lock.yml +++ b/.github/workflows/daily-graft-intelligence.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/gh.md -# - shared/mcp/graft.md -# - shared/noop-reminder.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md +# - shared/gh.md +# - shared/mcp/graft.md +# - shared/noop-reminder.md # # Secrets used: # - GH_AW_DEFAULT_OTLP_HEADERS diff --git a/.github/workflows/daily-issues-report.lock.yml b/.github/workflows/daily-issues-report.lock.yml index 57067937b26..9ffa3affd4a 100644 --- a/.github/workflows/daily-issues-report.lock.yml +++ b/.github/workflows/daily-issues-report.lock.yml @@ -28,15 +28,15 @@ # Resolved workflow manifest: # Imports: # - shared/github-guard-policy.md +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - ../skills/jqschema/SKILL.md # - shared/issues-data-fetch.md +# - shared/python-dataviz.md +# - shared/trends.md # - shared/python-nlp.md # - shared/otlp.md -# - shared/daily-audit-discussion.md -# - shared/reporting.md # - shared/daily-audit-base.md -# - shared/python-dataviz.md -# - shared/trends.md # # Secrets used: # - COPILOT_GITHUB_TOKEN @@ -665,35 +665,6 @@ jobs: GITHUB_GRAPHQL_URL: https://localhost:18443/api/graphql GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} NODE_EXTRA_CA_CERTS: /tmp/gh-aw/proxy-logs/proxy-tls/ca.crt - - name: Setup Python NLP environment - run: | - mkdir -p /tmp/gh-aw/python/{data,charts,artifacts} - # Create a virtual environment for proper package isolation (avoids --break-system-packages) - # Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/) - # Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC). - # This must match shared/python-dataviz.md so either import can create the shared environment first. - if [ ! -d /tmp/gh-aw/python/venv ]; then - uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv - fi - echo "/tmp/gh-aw/python/venv/bin" >> "$GITHUB_PATH" - /tmp/gh-aw/python/venv/bin/pip install --quiet nltk scikit-learn textblob wordcloud - - # Download required NLTK corpora - /tmp/gh-aw/python/venv/bin/python3 -c " - import nltk - for corpus in ['punkt_tab', 'stopwords', 'vader_lexicon', 'averaged_perceptron_tagger_eng']: - nltk.download(corpus, quiet=True) - print('NLTK corpora ready') - " - - /tmp/gh-aw/python/venv/bin/python3 -c "import sklearn; print(f'scikit-learn {sklearn.__version__}')" - env: - GH_HOST: ${{ env.GH_HOST || 'github.com' }} - GH_REPO: ${{ github.repository }} - GITHUB_API_URL: https://localhost:18443/api/v3 - GITHUB_GRAPHQL_URL: https://localhost:18443/api/graphql - NODE_EXTRA_CA_CERTS: /tmp/gh-aw/proxy-logs/proxy-tls/ca.crt - UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python - name: Setup Python environment run: | # Create working directory for Python scripts @@ -756,6 +727,35 @@ jobs: /tmp/gh-aw/python/*.py /tmp/gh-aw/python/data/* retention-days: 30 + - name: Setup Python NLP environment + run: | + mkdir -p /tmp/gh-aw/python/{data,charts,artifacts} + # Create a virtual environment for proper package isolation (avoids --break-system-packages) + # Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/) + # Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC). + # This must match shared/python-dataviz.md so either import can create the shared environment first. + if [ ! -d /tmp/gh-aw/python/venv ]; then + uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv + fi + echo "/tmp/gh-aw/python/venv/bin" >> "$GITHUB_PATH" + /tmp/gh-aw/python/venv/bin/pip install --quiet nltk scikit-learn textblob wordcloud + + # Download required NLTK corpora + /tmp/gh-aw/python/venv/bin/python3 -c " + import nltk + for corpus in ['punkt_tab', 'stopwords', 'vader_lexicon', 'averaged_perceptron_tagger_eng']: + nltk.download(corpus, quiet=True) + print('NLTK corpora ready') + " + + /tmp/gh-aw/python/venv/bin/python3 -c "import sklearn; print(f'scikit-learn {sklearn.__version__}')" + env: + GH_HOST: ${{ env.GH_HOST || 'github.com' }} + GH_REPO: ${{ github.repository }} + GITHUB_API_URL: https://localhost:18443/api/v3 + GITHUB_GRAPHQL_URL: https://localhost:18443/api/graphql + NODE_EXTRA_CA_CERTS: /tmp/gh-aw/proxy-logs/proxy-tls/ca.crt + UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python - name: Configure Git credentials env: GITHUB_REPOSITORY: ${{ github.repository }} diff --git a/.github/workflows/daily-malicious-code-scan.lock.yml b/.github/workflows/daily-malicious-code-scan.lock.yml index 71512ac17f8..2cb7befd963 100644 --- a/.github/workflows/daily-malicious-code-scan.lock.yml +++ b/.github/workflows/daily-malicious-code-scan.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/security-analysis-base.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml index 1cd423c7ac3..ab004e8382b 100644 --- a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml +++ b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md +# - shared/daily-audit-discussion.md # - shared/safe-output-app.md # - shared/mcp/serena.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-multi-device-docs-tester.lock.yml b/.github/workflows/daily-multi-device-docs-tester.lock.yml index 585d151885a..4954d7b98c4 100644 --- a/.github/workflows/daily-multi-device-docs-tester.lock.yml +++ b/.github/workflows/daily-multi-device-docs-tester.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-news.lock.yml b/.github/workflows/daily-news.lock.yml index 1cdfe7232b1..3bbf9448469 100644 --- a/.github/workflows/daily-news.lock.yml +++ b/.github/workflows/daily-news.lock.yml @@ -30,12 +30,12 @@ # - shared/repo-memory-standard.md # - shared/mcp/tavily.md # - ../skills/jqschema/SKILL.md -# - shared/otlp.md -# - shared/reporting.md # - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md # - shared/python-dataviz.md # - shared/trends.md +# - shared/otlp.md +# - shared/reporting.md +# - shared/daily-audit-base.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/daily-observability-report.lock.yml b/.github/workflows/daily-observability-report.lock.yml index 7206e0d4228..4ce473a6ccb 100644 --- a/.github/workflows/daily-observability-report.lock.yml +++ b/.github/workflows/daily-observability-report.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/meta-analysis-base.md +# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-performance-summary.lock.yml b/.github/workflows/daily-performance-summary.lock.yml index f16529ceade..7ce38a27a55 100644 --- a/.github/workflows/daily-performance-summary.lock.yml +++ b/.github/workflows/daily-performance-summary.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: +# - shared/trending-charts-simple.md +# - shared/daily-audit-discussion.md # - shared/github-queries-mcp-script.md # - shared/reporting.md # - shared/otlp.md -# - shared/trending-charts-simple.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # diff --git a/.github/workflows/daily-regulatory.lock.yml b/.github/workflows/daily-regulatory.lock.yml index 2159e5d3e65..9b7eea027c2 100644 --- a/.github/workflows/daily-regulatory.lock.yml +++ b/.github/workflows/daily-regulatory.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md # - shared/github-queries-mcp-script.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-reliability-review.lock.yml b/.github/workflows/daily-reliability-review.lock.yml index bcc68e1d417..765eaf6bd4d 100644 --- a/.github/workflows/daily-reliability-review.lock.yml +++ b/.github/workflows/daily-reliability-review.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/opencode.md +# - shared/activation-app.md # - shared/sentry.md # - shared/mcp/sentry.md # - shared/reporting.md -# - shared/activation-app.md # - shared/daily-issue-base.md # # Secrets used: diff --git a/.github/workflows/daily-rendering-scripts-verifier.lock.yml b/.github/workflows/daily-rendering-scripts-verifier.lock.yml index dae56e9884f..98dab9c9342 100644 --- a/.github/workflows/daily-rendering-scripts-verifier.lock.yml +++ b/.github/workflows/daily-rendering-scripts-verifier.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/meta-analysis-base.md # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md # - shared/daily-audit-discussion.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-repo-chronicle.lock.yml b/.github/workflows/daily-repo-chronicle.lock.yml index 8ea362d807f..3b06e6ebc0a 100644 --- a/.github/workflows/daily-repo-chronicle.lock.yml +++ b/.github/workflows/daily-repo-chronicle.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/reporting.md # - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md # - shared/python-dataviz.md # - shared/trends.md +# - shared/otlp.md +# - shared/reporting.md +# - shared/daily-audit-base.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/daily-safe-output-integrator.lock.yml b/.github/workflows/daily-safe-output-integrator.lock.yml index 34a6eb540ea..193fe6757be 100644 --- a/.github/workflows/daily-safe-output-integrator.lock.yml +++ b/.github/workflows/daily-safe-output-integrator.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-safe-output-optimizer.lock.yml b/.github/workflows/daily-safe-output-optimizer.lock.yml index 8618a793fcc..7d5b34a33a7 100644 --- a/.github/workflows/daily-safe-output-optimizer.lock.yml +++ b/.github/workflows/daily-safe-output-optimizer.lock.yml @@ -31,9 +31,9 @@ # - shared/aw-logs-24h-fetch-setup.md # - shared/activation-app.md # - ../skills/jqschema/SKILL.md +# - shared/daily-audit-discussion.md # - shared/otlp.md # - shared/reporting.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-safe-outputs-conformance.lock.yml b/.github/workflows/daily-safe-outputs-conformance.lock.yml index 88b98e86620..7409fa056be 100644 --- a/.github/workflows/daily-safe-outputs-conformance.lock.yml +++ b/.github/workflows/daily-safe-outputs-conformance.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-secrets-analysis.lock.yml b/.github/workflows/daily-secrets-analysis.lock.yml index 35cfa61be32..2d7f2590e6e 100644 --- a/.github/workflows/daily-secrets-analysis.lock.yml +++ b/.github/workflows/daily-secrets-analysis.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md # - shared/otlp.md # - shared/reporting.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-security-observability.lock.yml b/.github/workflows/daily-security-observability.lock.yml index 745ae8987a8..efad2330095 100644 --- a/.github/workflows/daily-security-observability.lock.yml +++ b/.github/workflows/daily-security-observability.lock.yml @@ -28,11 +28,11 @@ # Resolved workflow manifest: # Imports: # - shared/meta-analysis-base.md -# - shared/python-dataviz.md -# - shared/otlp.md # - shared/trending-charts-simple.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/python-dataviz.md +# - shared/otlp.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # @@ -570,32 +570,32 @@ jobs: with: key: agentic-logs path: .github/aw/logs - - name: Setup Python environment - run: "# Create working directory for Python scripts\nmkdir -p /tmp/gh-aw/python\nmkdir -p /tmp/gh-aw/python/data\nmkdir -p /tmp/gh-aw/python/charts\nmkdir -p /tmp/gh-aw/python/artifacts\n\necho \"Python environment setup complete\"\necho \"Working directory: /tmp/gh-aw/python\"\necho \"Data directory: /tmp/gh-aw/python/data\"\necho \"Charts directory: /tmp/gh-aw/python/charts\"\necho \"Artifacts directory: /tmp/gh-aw/python/artifacts\"\n" - env: UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python - name: Install Python scientific libraries - run: "# Create a virtual environment for proper package isolation (avoids --break-system-packages)\n# Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/)\n# Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC).\n# This must match shared/python-nlp.md so either import can create the shared environment first.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/pip install --quiet numpy pandas matplotlib seaborn scipy\n\n# Verify installations\n/tmp/gh-aw/python/venv/bin/python3 -c \"import numpy; print(f'NumPy {numpy.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import pandas; print(f'Pandas {pandas.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import matplotlib; print(f'Matplotlib {matplotlib.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import seaborn; print(f'Seaborn {seaborn.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import scipy; print(f'SciPy {scipy.__version__} installed')\"\n\necho \"All scientific libraries installed successfully\"\n" + name: Setup Python environment + run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/python/{data,charts,artifacts}\n# The agent sandbox cannot run the runner's CPython (glibc mismatch) and only ships\n# PyPy, which has no wheels for the chart libraries — installing them from inside the\n# sandbox builds NumPy/SciPy from source and exhausts the runner disk. Install a\n# portable uv-managed CPython plus the chart libraries under /tmp/gh-aw, which is\n# mounted read-write into the sandbox, so the agent can import them directly.\n# This must match shared/python-dataviz.md and shared/python-nlp.md so either import can\n# create the shared environment first; never recreate it, or a sibling import's packages\n# (for example the NLP libraries) would be discarded.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\nuv pip install --quiet --python /tmp/gh-aw/python/venv/bin/python numpy pandas matplotlib seaborn scipy\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/python -c \"import numpy,pandas,matplotlib,seaborn,scipy;print('chart-libraries-ready')\"\n" - if: always() name: Upload source files and data uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: if-no-files-found: warn - name: python-source-and-data + name: trending-source-and-data path: | /tmp/gh-aw/python/*.py /tmp/gh-aw/python/data/* retention-days: 30 + - name: Setup Python environment + run: "# Create working directory for Python scripts\nmkdir -p /tmp/gh-aw/python\nmkdir -p /tmp/gh-aw/python/data\nmkdir -p /tmp/gh-aw/python/charts\nmkdir -p /tmp/gh-aw/python/artifacts\n\necho \"Python environment setup complete\"\necho \"Working directory: /tmp/gh-aw/python\"\necho \"Data directory: /tmp/gh-aw/python/data\"\necho \"Charts directory: /tmp/gh-aw/python/charts\"\necho \"Artifacts directory: /tmp/gh-aw/python/artifacts\"\n" - env: UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python - name: Setup Python environment - run: "set -euo pipefail\nmkdir -p /tmp/gh-aw/python/{data,charts,artifacts}\n# The agent sandbox cannot run the runner's CPython (glibc mismatch) and only ships\n# PyPy, which has no wheels for the chart libraries — installing them from inside the\n# sandbox builds NumPy/SciPy from source and exhausts the runner disk. Install a\n# portable uv-managed CPython plus the chart libraries under /tmp/gh-aw, which is\n# mounted read-write into the sandbox, so the agent can import them directly.\n# This must match shared/python-dataviz.md and shared/python-nlp.md so either import can\n# create the shared environment first; never recreate it, or a sibling import's packages\n# (for example the NLP libraries) would be discarded.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\nuv pip install --quiet --python /tmp/gh-aw/python/venv/bin/python numpy pandas matplotlib seaborn scipy\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/python -c \"import numpy,pandas,matplotlib,seaborn,scipy;print('chart-libraries-ready')\"\n" + name: Install Python scientific libraries + run: "# Create a virtual environment for proper package isolation (avoids --break-system-packages)\n# Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/)\n# Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC).\n# This must match shared/python-nlp.md so either import can create the shared environment first.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/pip install --quiet numpy pandas matplotlib seaborn scipy\n\n# Verify installations\n/tmp/gh-aw/python/venv/bin/python3 -c \"import numpy; print(f'NumPy {numpy.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import pandas; print(f'Pandas {pandas.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import matplotlib; print(f'Matplotlib {matplotlib.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import seaborn; print(f'Seaborn {seaborn.__version__} installed')\"\n/tmp/gh-aw/python/venv/bin/python3 -c \"import scipy; print(f'SciPy {scipy.__version__} installed')\"\n\necho \"All scientific libraries installed successfully\"\n" - if: always() name: Upload source files and data uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: if-no-files-found: warn - name: trending-source-and-data + name: python-source-and-data path: | /tmp/gh-aw/python/*.py /tmp/gh-aw/python/data/* diff --git a/.github/workflows/daily-security-red-team.lock.yml b/.github/workflows/daily-security-red-team.lock.yml index 75d1fc0498f..b1b51f31676 100644 --- a/.github/workflows/daily-security-red-team.lock.yml +++ b/.github/workflows/daily-security-red-team.lock.yml @@ -29,9 +29,9 @@ # Imports: # - shared/opencode.md # - shared/security-analysis-base.md +# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-spdd-spec-planner.lock.yml b/.github/workflows/daily-spdd-spec-planner.lock.yml index 886065e7fb0..e02b6dad301 100644 --- a/.github/workflows/daily-spdd-spec-planner.lock.yml +++ b/.github/workflows/daily-spdd-spec-planner.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md +# - shared/otlp.md # # Secrets used: # - GH_AW_AGENT_TOKEN diff --git a/.github/workflows/daily-team-evolution-insights.lock.yml b/.github/workflows/daily-team-evolution-insights.lock.yml index 3bf7ec3f8c6..04806f0977d 100644 --- a/.github/workflows/daily-team-evolution-insights.lock.yml +++ b/.github/workflows/daily-team-evolution-insights.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/goose.md +# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/daily-testify-uber-super-expert.lock.yml b/.github/workflows/daily-testify-uber-super-expert.lock.yml index 238797097cf..1af4f2d3679 100644 --- a/.github/workflows/daily-testify-uber-super-expert.lock.yml +++ b/.github/workflows/daily-testify-uber-super-expert.lock.yml @@ -28,14 +28,14 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md -# - shared/safe-output-app.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md +# - shared/safe-output-app.md +# - shared/otlp.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/daily-token-consumption-report.lock.yml b/.github/workflows/daily-token-consumption-report.lock.yml index 1dfb84324ff..1b93fc97525 100644 --- a/.github/workflows/daily-token-consumption-report.lock.yml +++ b/.github/workflows/daily-token-consumption-report.lock.yml @@ -30,9 +30,9 @@ # - shared/goose.md # - shared/mcp/sentry.md # - shared/mcp/grafana.md +# - shared/daily-audit-discussion.md # - shared/reporting.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/dead-code-remover.lock.yml b/.github/workflows/dead-code-remover.lock.yml index 1bfcbbbe0af..6ada4394113 100644 --- a/.github/workflows/dead-code-remover.lock.yml +++ b/.github/workflows/dead-code-remover.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md +# - shared/otlp.md # # Secrets used: # - GH_AW_CI_TRIGGER_TOKEN diff --git a/.github/workflows/delight.lock.yml b/.github/workflows/delight.lock.yml index a77a7c37639..f0f58b43bb6 100644 --- a/.github/workflows/delight.lock.yml +++ b/.github/workflows/delight.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md +# - shared/daily-audit-discussion.md # - shared/repo-memory-standard.md # - shared/otlp.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/dependabot-burner.lock.yml b/.github/workflows/dependabot-burner.lock.yml index bb2475fbd10..6b28bc32b5a 100644 --- a/.github/workflows/dependabot-burner.lock.yml +++ b/.github/workflows/dependabot-burner.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/mcp-pagination.md +# - shared/activation-app.md # - shared/otlp.md # - shared/reporting.md -# - shared/activation-app.md # - shared/daily-pr-base.md # # Secrets used: diff --git a/.github/workflows/detection-analysis-report.lock.yml b/.github/workflows/detection-analysis-report.lock.yml index 8a05673c5fb..7265204fb92 100644 --- a/.github/workflows/detection-analysis-report.lock.yml +++ b/.github/workflows/detection-analysis-report.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/aw-logs-24h-fetch-setup.md -# - shared/reporting.md # - shared/trending-charts-simple.md # - shared/daily-audit-discussion.md # - shared/otlp.md +# - shared/aw-logs-24h-fetch-setup.md +# - shared/reporting.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # @@ -561,10 +561,6 @@ jobs: with: key: agentic-logs path: .github/aw/logs - - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Download logs from last 24 hours - run: ./gh-aw logs --start-date -1d --count 3000 -o /tmp/gh-aw/aw-mcp/logs - env: UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python name: Setup Python environment @@ -579,6 +575,10 @@ jobs: /tmp/gh-aw/python/*.py /tmp/gh-aw/python/data/* retention-days: 30 + - env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + name: Download logs from last 24 hours + run: ./gh-aw logs --start-date -1d --count 3000 -o /tmp/gh-aw/aw-mcp/logs - name: Configure Git credentials env: diff --git a/.github/workflows/developer-docs-consolidator.lock.yml b/.github/workflows/developer-docs-consolidator.lock.yml index d822e9a4208..ecf06e0d4df 100644 --- a/.github/workflows/developer-docs-consolidator.lock.yml +++ b/.github/workflows/developer-docs-consolidator.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/docs-noob-tester.lock.yml b/.github/workflows/docs-noob-tester.lock.yml index 9b36fd03f53..d4b45c5f3b3 100644 --- a/.github/workflows/docs-noob-tester.lock.yml +++ b/.github/workflows/docs-noob-tester.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - shared/docs-server-lifecycle.md # - shared/keep-it-short.md # - shared/otlp.md -# - shared/daily-audit-discussion.md -# - shared/reporting.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/duplicate-code-detector.lock.yml b/.github/workflows/duplicate-code-detector.lock.yml index 7ffdfeb44f9..1dd91994649 100644 --- a/.github/workflows/duplicate-code-detector.lock.yml +++ b/.github/workflows/duplicate-code-detector.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/reporting.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/reporting.md # - shared/go-source-analysis.md # # Secrets used: diff --git a/.github/workflows/eslint-refiner.lock.yml b/.github/workflows/eslint-refiner.lock.yml index 6d4426e3c12..f2d9a2e18bb 100644 --- a/.github/workflows/eslint-refiner.lock.yml +++ b/.github/workflows/eslint-refiner.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md # - shared/otlp.md # - shared/reporting.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/example-workflow-analyzer.lock.yml b/.github/workflows/example-workflow-analyzer.lock.yml index e9f542eb292..a00b8d8dd5c 100644 --- a/.github/workflows/example-workflow-analyzer.lock.yml +++ b/.github/workflows/example-workflow-analyzer.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/meta-analysis-base.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/github-mcp-structural-analysis.lock.yml b/.github/workflows/github-mcp-structural-analysis.lock.yml index 8315b867abc..e3886135f73 100644 --- a/.github/workflows/github-mcp-structural-analysis.lock.yml +++ b/.github/workflows/github-mcp-structural-analysis.lock.yml @@ -29,10 +29,10 @@ # Imports: # - shared/mcp-pagination.md # - shared/github-mcp-pagination-wrappers.md -# - shared/python-dataviz.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/python-dataviz.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/github-mcp-tools-report.lock.yml b/.github/workflows/github-mcp-tools-report.lock.yml index 07092fd077a..c69516ecd1a 100644 --- a/.github/workflows/github-mcp-tools-report.lock.yml +++ b/.github/workflows/github-mcp-tools-report.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/github-remote-mcp-auth-test.lock.yml b/.github/workflows/github-remote-mcp-auth-test.lock.yml index 13e42c38cd9..7903913f832 100644 --- a/.github/workflows/github-remote-mcp-auth-test.lock.yml +++ b/.github/workflows/github-remote-mcp-auth-test.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/glossary-maintainer.lock.yml b/.github/workflows/glossary-maintainer.lock.yml index db9326dd977..ee479405499 100644 --- a/.github/workflows/glossary-maintainer.lock.yml +++ b/.github/workflows/glossary-maintainer.lock.yml @@ -30,10 +30,10 @@ # - ../skills/documentation/SKILL.md # - ../agents/technical-doc-writer.agent.md # - shared/ai-coding-dictionary.md -# - shared/otlp.md -# - shared/reporting.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/reporting.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/go-fan.lock.yml b/.github/workflows/go-fan.lock.yml index 743d1eb4f1d..e2f7f832b8c 100644 --- a/.github/workflows/go-fan.lock.yml +++ b/.github/workflows/go-fan.lock.yml @@ -27,13 +27,13 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md +# - shared/otlp.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/grumpy-reviewer.lock.yml b/.github/workflows/grumpy-reviewer.lock.yml index b3da46a1ce7..b19f3489aeb 100644 --- a/.github/workflows/grumpy-reviewer.lock.yml +++ b/.github/workflows/grumpy-reviewer.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/otlp.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/impeccable-skills-reviewer.lock.yml b/.github/workflows/impeccable-skills-reviewer.lock.yml index 1488bbe9843..3d2e68ae6a5 100644 --- a/.github/workflows/impeccable-skills-reviewer.lock.yml +++ b/.github/workflows/impeccable-skills-reviewer.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/reporting.md -# - shared/otlp.md -# - shared/pr-diff-data-fetch.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/reporting.md +# - shared/otlp.md +# - shared/pr-diff-data-fetch.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/linter-miner.lock.yml b/.github/workflows/linter-miner.lock.yml index 649a2f444c7..aaffd8453cf 100644 --- a/.github/workflows/linter-miner.lock.yml +++ b/.github/workflows/linter-miner.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/reporting.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/reporting.md # # Secrets used: # - DOCKER_PAT diff --git a/.github/workflows/lockfile-stats.lock.yml b/.github/workflows/lockfile-stats.lock.yml index 206aba3b605..1e127515bf3 100644 --- a/.github/workflows/lockfile-stats.lock.yml +++ b/.github/workflows/lockfile-stats.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/mattpocock-skills-reviewer.lock.yml b/.github/workflows/mattpocock-skills-reviewer.lock.yml index 1533e9e01c3..9a1dc908393 100644 --- a/.github/workflows/mattpocock-skills-reviewer.lock.yml +++ b/.github/workflows/mattpocock-skills-reviewer.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/pr-diff-data-fetch.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/otlp.md +# - shared/pr-diff-data-fetch.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/mcp-inspector.lock.yml b/.github/workflows/mcp-inspector.lock.yml index 814a3ae9d19..9505ddfddb9 100644 --- a/.github/workflows/mcp-inspector.lock.yml +++ b/.github/workflows/mcp-inspector.lock.yml @@ -27,6 +27,8 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - shared/mcp/ast-grep.md # - shared/mcp/datadog.md # - shared/mcp/deepwiki.md @@ -34,12 +36,10 @@ # - shared/mcp/sentry.md # - shared/mcp/slack.md # - shared/mcp/tavily.md -# - shared/otlp.md -# - shared/daily-audit-discussion.md -# - shared/reporting.md -# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/ponytail-reviewer.lock.yml b/.github/workflows/ponytail-reviewer.lock.yml index 1083e1be057..c682e7c399d 100644 --- a/.github/workflows/ponytail-reviewer.lock.yml +++ b/.github/workflows/ponytail-reviewer.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/pr-diff-data-fetch.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/otlp.md +# - shared/pr-diff-data-fetch.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/portfolio-analyst.lock.yml b/.github/workflows/portfolio-analyst.lock.yml index 376598e751d..cdf49cc2069 100644 --- a/.github/workflows/portfolio-analyst.lock.yml +++ b/.github/workflows/portfolio-analyst.lock.yml @@ -29,9 +29,9 @@ # Imports: # - shared/mcp/sentry.md # - shared/mcp/grafana.md -# - shared/reporting.md # - shared/python-dataviz.md # - shared/trends.md +# - shared/reporting.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/pr-code-quality-reviewer.lock.yml b/.github/workflows/pr-code-quality-reviewer.lock.yml index 735c67759e7..b8eb8eb118e 100644 --- a/.github/workflows/pr-code-quality-reviewer.lock.yml +++ b/.github/workflows/pr-code-quality-reviewer.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/pr-diff-data-fetch.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/otlp.md +# - shared/pr-diff-data-fetch.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/pr-nitpick-reviewer.lock.yml b/.github/workflows/pr-nitpick-reviewer.lock.yml index c494b019cfc..2d7a564fba9 100644 --- a/.github/workflows/pr-nitpick-reviewer.lock.yml +++ b/.github/workflows/pr-nitpick-reviewer.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/reporting.md -# - shared/otlp.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/reporting.md +# - shared/otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/pr-triage-agent.lock.yml b/.github/workflows/pr-triage-agent.lock.yml index 7db7fc7381f..21c1c313d2c 100644 --- a/.github/workflows/pr-triage-agent.lock.yml +++ b/.github/workflows/pr-triage-agent.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md -# - shared/otlp.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/prompt-clustering-analysis.lock.yml b/.github/workflows/prompt-clustering-analysis.lock.yml index 9d0883e8f7c..d6a243d1331 100644 --- a/.github/workflows/prompt-clustering-analysis.lock.yml +++ b/.github/workflows/prompt-clustering-analysis.lock.yml @@ -28,13 +28,13 @@ # Resolved workflow manifest: # Imports: # - shared/meta-analysis-base.md +# - shared/trending-charts-simple.md +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - ../skills/jqschema/SKILL.md # - shared/copilot-pr-data-fetch.md # - shared/python-nlp.md # - shared/otlp.md -# - shared/trending-charts-simple.md -# - shared/daily-audit-discussion.md -# - shared/reporting.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # @@ -570,18 +570,6 @@ jobs: with: key: agentic-logs path: .github/aw/logs - - name: Install gh CLI - run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_gh_cli.sh" - - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Fetch Copilot PR data - run: "# Create output directories\nmkdir -p /tmp/gh-aw/agent/pr-data\nmkdir -p /tmp/gh-aw/cache-memory\n\n# Cache files use stable names so restored caches from previous runs are reusable\n# regardless of the date they were written on. Freshness is decided by file age.\nCACHE_DIR=\"/tmp/gh-aw/cache-memory\"\nCACHE_FILE=\"$CACHE_DIR/copilot-prs-latest.json\"\nCACHE_SCHEMA_FILE=\"$CACHE_DIR/copilot-prs-latest-schema.json\"\nCACHE_MAX_AGE_SECONDS=\"${CACHE_MAX_AGE_SECONDS:-21600}\"\n\n# Returns success when the file exists, is non-empty and younger than the max age.\ncache_is_fresh() {\n cache_path=\"$1\"\n [ -s \"$cache_path\" ] || return 1\n cache_mtime=$(date -r \"$cache_path\" '+%s' 2>/dev/null) || return 1\n [ -n \"$cache_mtime\" ] || return 1\n now=$(date '+%s')\n [ \"$((now - cache_mtime))\" -lt \"$CACHE_MAX_AGE_SECONDS\" ]\n}\n\n# Check if restored cache data is still fresh enough to reuse\nif cache_is_fresh \"$CACHE_FILE\"; then\n CACHE_AGE_MINUTES=$(( ( $(date '+%s') - $(date -r \"$CACHE_FILE\" '+%s') ) / 60 ))\n echo \"✓ Found cached PR data (${CACHE_AGE_MINUTES} minutes old)\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n \n # Regenerate schema if missing\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n \n echo \"Using cached data written ${CACHE_AGE_MINUTES} minutes ago\"\n echo \"Total PRs in cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nelse\n echo \"⬇ Downloading fresh PR data...\"\n \n # Calculate date 30 days ago\n DATE_30_DAYS_AGO=$(date -d '30 days ago' '+%Y-%m-%d' 2>/dev/null || date -v-30d '+%Y-%m-%d')\n\n # Search for PRs from copilot/* branches in the last 30 days using gh CLI\n # Using branch prefix search (head:copilot/) instead of author for reliability\n echo \"Fetching Copilot PRs from the last 30 days...\"\n FETCH_TMP=\"${RUNNER_TEMP:-/tmp}/copilot-prs-fetch.json\"\n rm -f \"$FETCH_TMP\"\n FETCH_OK=true\n gh pr list --repo \"$GITHUB_REPOSITORY\" \\\n --search \"head:copilot/ created:>=${DATE_30_DAYS_AGO}\" \\\n --state all \\\n --json number,title,author,headRefName,createdAt,state,url,body,labels,updatedAt,closedAt,mergedAt \\\n --limit 1000 \\\n > \"$FETCH_TMP\" || FETCH_OK=false\n\n if [ \"$FETCH_OK\" != \"true\" ] || ! jq -e 'type == \"array\"' \"$FETCH_TMP\" >/dev/null 2>&1; then\n # Transient GitHub API failures (e.g. 503) must not fail the whole run when\n # stale cached data is still available; fall back to it instead.\n if [ -s \"$CACHE_FILE\" ]; then\n echo \"::warning::Failed to fetch Copilot PR data; falling back to stale cached data\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n echo \"Total PRs in stale cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\n echo \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\n echo \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n exit 0\n fi\n echo \"::error::Failed to fetch Copilot PR data and no cached data is available\"\n exit 1\n fi\n\n cp \"$FETCH_TMP\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n rm -f \"$FETCH_TMP\"\n\n # Generate schema for reference\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n\n # Store in cache under stable names so future runs can reuse it on any date\n cp /tmp/gh-aw/agent/pr-data/copilot-prs.json \"$CACHE_FILE\"\n cp /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json \"$CACHE_SCHEMA_FILE\"\n\n # Drop legacy date-keyed cache entries so the cache does not grow unbounded\n rm -f \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9].json \\\n \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]-schema.json 2>/dev/null || true\n\n echo \"✓ PR data saved to cache: $(basename \"$CACHE_FILE\")\"\n echo \"Total PRs found: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nfi\n\n# Always ensure data is available at expected locations for backward compatibility\necho \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\necho \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n" - - env: - UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python - name: Setup Python NLP environment - run: "mkdir -p /tmp/gh-aw/python/{data,charts,artifacts}\n# Create a virtual environment for proper package isolation (avoids --break-system-packages)\n# Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/)\n# Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC).\n# This must match shared/python-dataviz.md so either import can create the shared environment first.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/pip install --quiet nltk scikit-learn textblob wordcloud\n\n# Download required NLTK corpora\n/tmp/gh-aw/python/venv/bin/python3 -c \"\nimport nltk\nfor corpus in ['punkt_tab', 'stopwords', 'vader_lexicon', 'averaged_perceptron_tagger_eng']:\n nltk.download(corpus, quiet=True)\nprint('NLTK corpora ready')\n\"\n\n/tmp/gh-aw/python/venv/bin/python3 -c \"import sklearn; print(f'scikit-learn {sklearn.__version__}')\"\n" - env: UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python name: Setup Python environment @@ -596,6 +584,18 @@ jobs: /tmp/gh-aw/python/*.py /tmp/gh-aw/python/data/* retention-days: 30 + - name: Install gh CLI + run: | + bash "${RUNNER_TEMP}/gh-aw/actions/install_gh_cli.sh" + - env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + name: Fetch Copilot PR data + run: "# Create output directories\nmkdir -p /tmp/gh-aw/agent/pr-data\nmkdir -p /tmp/gh-aw/cache-memory\n\n# Cache files use stable names so restored caches from previous runs are reusable\n# regardless of the date they were written on. Freshness is decided by file age.\nCACHE_DIR=\"/tmp/gh-aw/cache-memory\"\nCACHE_FILE=\"$CACHE_DIR/copilot-prs-latest.json\"\nCACHE_SCHEMA_FILE=\"$CACHE_DIR/copilot-prs-latest-schema.json\"\nCACHE_MAX_AGE_SECONDS=\"${CACHE_MAX_AGE_SECONDS:-21600}\"\n\n# Returns success when the file exists, is non-empty and younger than the max age.\ncache_is_fresh() {\n cache_path=\"$1\"\n [ -s \"$cache_path\" ] || return 1\n cache_mtime=$(date -r \"$cache_path\" '+%s' 2>/dev/null) || return 1\n [ -n \"$cache_mtime\" ] || return 1\n now=$(date '+%s')\n [ \"$((now - cache_mtime))\" -lt \"$CACHE_MAX_AGE_SECONDS\" ]\n}\n\n# Check if restored cache data is still fresh enough to reuse\nif cache_is_fresh \"$CACHE_FILE\"; then\n CACHE_AGE_MINUTES=$(( ( $(date '+%s') - $(date -r \"$CACHE_FILE\" '+%s') ) / 60 ))\n echo \"✓ Found cached PR data (${CACHE_AGE_MINUTES} minutes old)\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n \n # Regenerate schema if missing\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n \n echo \"Using cached data written ${CACHE_AGE_MINUTES} minutes ago\"\n echo \"Total PRs in cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nelse\n echo \"⬇ Downloading fresh PR data...\"\n \n # Calculate date 30 days ago\n DATE_30_DAYS_AGO=$(date -d '30 days ago' '+%Y-%m-%d' 2>/dev/null || date -v-30d '+%Y-%m-%d')\n\n # Search for PRs from copilot/* branches in the last 30 days using gh CLI\n # Using branch prefix search (head:copilot/) instead of author for reliability\n echo \"Fetching Copilot PRs from the last 30 days...\"\n FETCH_TMP=\"${RUNNER_TEMP:-/tmp}/copilot-prs-fetch.json\"\n rm -f \"$FETCH_TMP\"\n FETCH_OK=true\n gh pr list --repo \"$GITHUB_REPOSITORY\" \\\n --search \"head:copilot/ created:>=${DATE_30_DAYS_AGO}\" \\\n --state all \\\n --json number,title,author,headRefName,createdAt,state,url,body,labels,updatedAt,closedAt,mergedAt \\\n --limit 1000 \\\n > \"$FETCH_TMP\" || FETCH_OK=false\n\n if [ \"$FETCH_OK\" != \"true\" ] || ! jq -e 'type == \"array\"' \"$FETCH_TMP\" >/dev/null 2>&1; then\n # Transient GitHub API failures (e.g. 503) must not fail the whole run when\n # stale cached data is still available; fall back to it instead.\n if [ -s \"$CACHE_FILE\" ]; then\n echo \"::warning::Failed to fetch Copilot PR data; falling back to stale cached data\"\n cp \"$CACHE_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n if [ ! -s \"$CACHE_SCHEMA_FILE\" ]; then\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > \"$CACHE_SCHEMA_FILE\"\n fi\n cp \"$CACHE_SCHEMA_FILE\" /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n echo \"Total PRs in stale cache: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\n echo \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\n echo \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n exit 0\n fi\n echo \"::error::Failed to fetch Copilot PR data and no cached data is available\"\n exit 1\n fi\n\n cp \"$FETCH_TMP\" /tmp/gh-aw/agent/pr-data/copilot-prs.json\n rm -f \"$FETCH_TMP\"\n\n # Generate schema for reference\n ./.github/skills/jqschema/jqschema.sh < /tmp/gh-aw/agent/pr-data/copilot-prs.json > /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\n\n # Store in cache under stable names so future runs can reuse it on any date\n cp /tmp/gh-aw/agent/pr-data/copilot-prs.json \"$CACHE_FILE\"\n cp /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json \"$CACHE_SCHEMA_FILE\"\n\n # Drop legacy date-keyed cache entries so the cache does not grow unbounded\n rm -f \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9].json \\\n \"$CACHE_DIR\"/copilot-prs-[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]-schema.json 2>/dev/null || true\n\n echo \"✓ PR data saved to cache: $(basename \"$CACHE_FILE\")\"\n echo \"Total PRs found: $(jq 'length' /tmp/gh-aw/agent/pr-data/copilot-prs.json)\"\nfi\n\n# Always ensure data is available at expected locations for backward compatibility\necho \"PR data available at: /tmp/gh-aw/agent/pr-data/copilot-prs.json\"\necho \"Schema available at: /tmp/gh-aw/agent/pr-data/copilot-prs-schema.json\"\n" + - env: + UV_PYTHON_INSTALL_DIR: /tmp/gh-aw/python/uv-python + name: Setup Python NLP environment + run: "mkdir -p /tmp/gh-aw/python/{data,charts,artifacts}\n# Create a virtual environment for proper package isolation (avoids --break-system-packages)\n# Use /tmp/gh-aw/python/venv to avoid polluting the agent artifact upload path (/tmp/gh-aw/agent/)\n# Use uv-managed CPython so the interpreter works inside the agent sandbox (runner CPython needs a newer GLIBC).\n# This must match shared/python-dataviz.md so either import can create the shared environment first.\nif [ ! -d /tmp/gh-aw/python/venv ]; then\n uv venv --python 3.12 --python-preference only-managed --seed /tmp/gh-aw/python/venv\nfi\necho \"/tmp/gh-aw/python/venv/bin\" >> \"$GITHUB_PATH\"\n/tmp/gh-aw/python/venv/bin/pip install --quiet nltk scikit-learn textblob wordcloud\n\n# Download required NLTK corpora\n/tmp/gh-aw/python/venv/bin/python3 -c \"\nimport nltk\nfor corpus in ['punkt_tab', 'stopwords', 'vader_lexicon', 'averaged_perceptron_tagger_eng']:\n nltk.download(corpus, quiet=True)\nprint('NLTK corpora ready')\n\"\n\n/tmp/gh-aw/python/venv/bin/python3 -c \"import sklearn; print(f'scikit-learn {sklearn.__version__}')\"\n" - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/purelock.lock.yml b/.github/workflows/purelock.lock.yml index bb1aae591b3..9d77514ce15 100644 --- a/.github/workflows/purelock.lock.yml +++ b/.github/workflows/purelock.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/reporting.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/reporting.md # # Secrets used: # - GH_AW_CI_TRIGGER_TOKEN diff --git a/.github/workflows/python-data-charts.lock.yml b/.github/workflows/python-data-charts.lock.yml index 20bf0513fe7..556cc4335b7 100644 --- a/.github/workflows/python-data-charts.lock.yml +++ b/.github/workflows/python-data-charts.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/reporting.md # - shared/python-dataviz.md # - shared/trends.md # - shared/charts-with-trending.md +# - shared/otlp.md +# - shared/reporting.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/refactoring-cadence.lock.yml b/.github/workflows/refactoring-cadence.lock.yml index c49a4868593..703667aa9b3 100644 --- a/.github/workflows/refactoring-cadence.lock.yml +++ b/.github/workflows/refactoring-cadence.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-issue-base.md +# - shared/otlp.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/refiner.lock.yml b/.github/workflows/refiner.lock.yml index d6580f86894..5dc86fdaaed 100644 --- a/.github/workflows/refiner.lock.yml +++ b/.github/workflows/refiner.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/reporting.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/otlp.md +# - shared/reporting.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/repo-audit-analyzer.lock.yml b/.github/workflows/repo-audit-analyzer.lock.yml index a913b4b590a..56612705314 100644 --- a/.github/workflows/repo-audit-analyzer.lock.yml +++ b/.github/workflows/repo-audit-analyzer.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/mcp-pagination.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/repository-quality-improver.lock.yml b/.github/workflows/repository-quality-improver.lock.yml index 3ec43cddf5d..227954012cc 100644 --- a/.github/workflows/repository-quality-improver.lock.yml +++ b/.github/workflows/repository-quality-improver.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/repository-quality-report-template.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/repository-quality-report-template.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/safe-output-health.lock.yml b/.github/workflows/safe-output-health.lock.yml index 793a31a7b03..133de8331af 100644 --- a/.github/workflows/safe-output-health.lock.yml +++ b/.github/workflows/safe-output-health.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: +# - shared/daily-audit-discussion.md +# - shared/reporting.md # - shared/aw-logs-24h-fetch.md # - ../skills/jqschema/SKILL.md # - shared/otlp.md -# - shared/daily-audit-discussion.md -# - shared/reporting.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/schema-consistency-checker.lock.yml b/.github/workflows/schema-consistency-checker.lock.yml index b4e34873906..0e3c67baf5b 100644 --- a/.github/workflows/schema-consistency-checker.lock.yml +++ b/.github/workflows/schema-consistency-checker.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md +# - shared/otlp.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/security-review.lock.yml b/.github/workflows/security-review.lock.yml index d20f40c20a2..3dae057dfaf 100644 --- a/.github/workflows/security-review.lock.yml +++ b/.github/workflows/security-review.lock.yml @@ -27,11 +27,11 @@ # # Resolved workflow manifest: # Imports: -# - shared/security-analysis-base.md -# - shared/otlp.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/security-analysis-base.md +# - shared/otlp.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/semantic-function-refactor.lock.yml b/.github/workflows/semantic-function-refactor.lock.yml index 7b6818fc569..90b9db61784 100644 --- a/.github/workflows/semantic-function-refactor.lock.yml +++ b/.github/workflows/semantic-function-refactor.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/reporting.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/reporting.md # - shared/go-source-analysis.md # # Secrets used: diff --git a/.github/workflows/sergo.lock.yml b/.github/workflows/sergo.lock.yml index 695d92ef510..6eef2f85eda 100644 --- a/.github/workflows/sergo.lock.yml +++ b/.github/workflows/sergo.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md -# - shared/reporting.md # - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/reporting.md +# - shared/daily-audit-base.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/skillet.lock.yml b/.github/workflows/skillet.lock.yml index 77193acf794..a1236419903 100644 --- a/.github/workflows/skillet.lock.yml +++ b/.github/workflows/skillet.lock.yml @@ -27,10 +27,10 @@ # # Resolved workflow manifest: # Imports: -# - shared/otlp.md # - shared/github-guard-policy.md # - shared/pr-code-review-config.md # - shared/pr-review-base.md +# - shared/otlp.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/slide-deck-maintainer.lock.yml b/.github/workflows/slide-deck-maintainer.lock.yml index 216389d950f..3ed5cc53696 100644 --- a/.github/workflows/slide-deck-maintainer.lock.yml +++ b/.github/workflows/slide-deck-maintainer.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md +# - shared/otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-codex.lock.yml b/.github/workflows/smoke-codex.lock.yml index 6b38265413f..bde14020b22 100644 --- a/.github/workflows/smoke-codex.lock.yml +++ b/.github/workflows/smoke-codex.lock.yml @@ -28,15 +28,15 @@ # Resolved workflow manifest: # Imports: # - shared/gh.md +# - shared/reporting.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # - shared/trufflehog.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md # - shared/playwright-title-test.md -# - shared/reporting.md -# - shared/reporting-otlp.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/smoke-copilot-aoai-apikey.lock.yml b/.github/workflows/smoke-copilot-aoai-apikey.lock.yml index f27a3cea2f1..39e19bb8c23 100644 --- a/.github/workflows/smoke-copilot-aoai-apikey.lock.yml +++ b/.github/workflows/smoke-copilot-aoai-apikey.lock.yml @@ -31,11 +31,11 @@ # - shared/gh.md # - shared/reporting.md # - shared/github-queries-mcp-script.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # - shared/otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-copilot-aoai-entra.lock.yml b/.github/workflows/smoke-copilot-aoai-entra.lock.yml index ea6097f1793..e4ecc26890d 100644 --- a/.github/workflows/smoke-copilot-aoai-entra.lock.yml +++ b/.github/workflows/smoke-copilot-aoai-entra.lock.yml @@ -31,12 +31,12 @@ # - shared/gh.md # - shared/reporting.md # - shared/github-queries-mcp-script.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # - shared/otlp.md # - shared/token-telemetry-check.md # - shared/azure-auth.md # - shared/smoke-test-brevity.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # # Frontmatter env variables: # - AZURE_CONFIG_DIR: shared/azure-auth.md @@ -810,11 +810,6 @@ jobs: env: GH_AW_SKILL_DIR: ".github/skills" run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_skills.sh" - - env: - GH_AW_AZURE_CLIENT_ID: adb907fd-188c-4029-b67f-2559d96b2f1b - GH_AW_AZURE_TENANT_ID: 398a6654-997b-47e9-b12b-9515b896b4de - name: Re-authenticate Azure CLI with OIDC - run: "if [ -z \"$GH_AW_AZURE_OIDC_TOKEN_FILE\" ] || [ ! -f \"$GH_AW_AZURE_OIDC_TOKEN_FILE\" ]; then\n echo \"::error::Azure OIDC token file not found — the Fetch Azure OIDC token step may have failed\"\n exit 1\nfi\nmkdir -p \"$AZURE_CONFIG_DIR\"\nchmod 700 \"$AZURE_CONFIG_DIR\"\ncleanup() {\n rm -f \"$GH_AW_AZURE_OIDC_TOKEN_FILE\"\n}\ntrap cleanup EXIT\naz login --service-principal \\\n --username \"$GH_AW_AZURE_CLIENT_ID\" \\\n --tenant \"$GH_AW_AZURE_TENANT_ID\" \\\n --federated-token \"$(cat \"$GH_AW_AZURE_OIDC_TOKEN_FILE\")\" \\\n --output none \\\n --only-show-errors\naz account show --output table\n" - name: Setup Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: @@ -822,6 +817,11 @@ jobs: go-version-file: go.mod - name: Verify Go installation run: go version + - env: + GH_AW_AZURE_CLIENT_ID: adb907fd-188c-4029-b67f-2559d96b2f1b + GH_AW_AZURE_TENANT_ID: 398a6654-997b-47e9-b12b-9515b896b4de + name: Re-authenticate Azure CLI with OIDC + run: "if [ -z \"$GH_AW_AZURE_OIDC_TOKEN_FILE\" ] || [ ! -f \"$GH_AW_AZURE_OIDC_TOKEN_FILE\" ]; then\n echo \"::error::Azure OIDC token file not found — the Fetch Azure OIDC token step may have failed\"\n exit 1\nfi\nmkdir -p \"$AZURE_CONFIG_DIR\"\nchmod 700 \"$AZURE_CONFIG_DIR\"\ncleanup() {\n rm -f \"$GH_AW_AZURE_OIDC_TOKEN_FILE\"\n}\ntrap cleanup EXIT\naz login --service-principal \\\n --username \"$GH_AW_AZURE_CLIENT_ID\" \\\n --tenant \"$GH_AW_AZURE_TENANT_ID\" \\\n --federated-token \"$(cat \"$GH_AW_AZURE_OIDC_TOKEN_FILE\")\" \\\n --output none \\\n --only-show-errors\naz account show --output table\n" - name: Download container images run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.28.12@sha256:390051be4ed1847f774fd8980b61d3a3523574c0175d00c3fc7cdf2002a88202 ghcr.io/github/gh-aw-firewall/api-proxy:0.28.12@sha256:d7d533d87c80d87ff91ac0e21e9299055c3beedff1536262b97ed700fb065a32 ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.12@sha256:5250629d48eaedfedf2e948785228e8da29eec2a83cbab58ea0751c14a7b021d ghcr.io/github/gh-aw-firewall/squid:0.28.12@sha256:52c34aca98d2a6833c329f1505912a6949c4fda16618c010c979bd59ea99254f ghcr.io/github/gh-aw-mcpg:v0.4.14@sha256:b2f0c2b2f17b5fbe809e5bb99dc185b6ddd70df25295dc63a6d526350334eff5 ghcr.io/github/gh-aw-node@sha256:bac2192f6374d6262116399b34fc5e143d576f82719e90a18261cae7480f4d4e ghcr.io/github/github-mcp-server:v1.11.0@sha256:fbec75de11c255213fa08d80fb166abe73d851fff631c51c0079872967720699 ghcr.io/oraios/serena:1.7.0@sha256:6c9459e4246a39c9deaa4f23fb05a526ac6e237b24c8e84a927a098fa1ab6730 diff --git a/.github/workflows/smoke-copilot-arm.lock.yml b/.github/workflows/smoke-copilot-arm.lock.yml index 1cde1a577b4..d366980324f 100644 --- a/.github/workflows/smoke-copilot-arm.lock.yml +++ b/.github/workflows/smoke-copilot-arm.lock.yml @@ -28,14 +28,14 @@ # Resolved workflow manifest: # Imports: # - shared/gh.md +# - shared/reporting.md # - shared/github-queries-mcp-script.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md -# - shared/reporting.md -# - shared/reporting-otlp.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-copilot.lock.yml b/.github/workflows/smoke-copilot.lock.yml index ca71862b1cc..420a6cbdd7b 100644 --- a/.github/workflows/smoke-copilot.lock.yml +++ b/.github/workflows/smoke-copilot.lock.yml @@ -31,12 +31,12 @@ # - shared/gh.md # - shared/reporting.md # - shared/github-queries-mcp-script.md +# - shared/mcp/serena.md +# - shared/mcp/serena-go.md # - shared/otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md # - shared/playwright-title-test.md -# - shared/mcp/serena.md -# - shared/mcp/serena-go.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-crush.lock.yml b/.github/workflows/smoke-crush.lock.yml index 9e135e5de11..ff1a520d025 100644 --- a/.github/workflows/smoke-crush.lock.yml +++ b/.github/workflows/smoke-crush.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/crush.md # - shared/gh.md +# - shared/reporting.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md -# - shared/reporting.md -# - shared/reporting-otlp.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/smoke-cursor.lock.yml b/.github/workflows/smoke-cursor.lock.yml index 76b9767f870..ea63eb27716 100644 --- a/.github/workflows/smoke-cursor.lock.yml +++ b/.github/workflows/smoke-cursor.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/cursor.md # - shared/gh.md +# - shared/reporting.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md -# - shared/reporting.md -# - shared/reporting-otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-deepseek-harness.lock.yml b/.github/workflows/smoke-deepseek-harness.lock.yml index 26e17f3e1ab..070345f7eae 100644 --- a/.github/workflows/smoke-deepseek-harness.lock.yml +++ b/.github/workflows/smoke-deepseek-harness.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/deepseek-harness.md # - shared/gh.md +# - shared/reporting.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md -# - shared/reporting.md -# - shared/reporting-otlp.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/smoke-gemini.lock.yml b/.github/workflows/smoke-gemini.lock.yml index a0cc993f2ce..15ae922ed66 100644 --- a/.github/workflows/smoke-gemini.lock.yml +++ b/.github/workflows/smoke-gemini.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: +# - shared/reporting.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md # - shared/playwright-title-test.md -# - shared/reporting.md -# - shared/reporting-otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-goose.lock.yml b/.github/workflows/smoke-goose.lock.yml index 91f72bf730f..b13a3e52361 100644 --- a/.github/workflows/smoke-goose.lock.yml +++ b/.github/workflows/smoke-goose.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/goose.md # - shared/gh.md +# - shared/reporting.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md -# - shared/reporting.md -# - shared/reporting-otlp.md # # Secrets used: # - GH_AW_GITHUB_MCP_SERVER_TOKEN diff --git a/.github/workflows/smoke-kiro.lock.yml b/.github/workflows/smoke-kiro.lock.yml index ec272c8ea77..0f6386d8ce0 100644 --- a/.github/workflows/smoke-kiro.lock.yml +++ b/.github/workflows/smoke-kiro.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/kiro.md # - shared/gh.md +# - shared/reporting.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md -# - shared/reporting.md -# - shared/reporting-otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-opencode.lock.yml b/.github/workflows/smoke-opencode.lock.yml index 10d2796fae8..8fb659493fc 100644 --- a/.github/workflows/smoke-opencode.lock.yml +++ b/.github/workflows/smoke-opencode.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/opencode.md # - shared/gh.md +# - shared/reporting.md # - shared/otlp.md +# - shared/reporting-otlp.md # - shared/token-telemetry-check.md # - shared/smoke-test-brevity.md -# - shared/reporting.md -# - shared/reporting-otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/smoke-pi.lock.yml b/.github/workflows/smoke-pi.lock.yml index 571605b8de5..873d13f1a93 100644 --- a/.github/workflows/smoke-pi.lock.yml +++ b/.github/workflows/smoke-pi.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/gh.md -# - shared/otlp.md -# - shared/smoke-test-brevity.md # - shared/reporting.md +# - shared/otlp.md # - shared/reporting-otlp.md +# - shared/smoke-test-brevity.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/spec-extractor.lock.yml b/.github/workflows/spec-extractor.lock.yml index 01b51171e1b..38d402253bb 100644 --- a/.github/workflows/spec-extractor.lock.yml +++ b/.github/workflows/spec-extractor.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md -# - shared/otlp.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md +# - shared/otlp.md # # Secrets used: # - GH_AW_CI_TRIGGER_TOKEN diff --git a/.github/workflows/spec-librarian.lock.yml b/.github/workflows/spec-librarian.lock.yml index 1cf9a8f6ac2..26294875ffb 100644 --- a/.github/workflows/spec-librarian.lock.yml +++ b/.github/workflows/spec-librarian.lock.yml @@ -29,12 +29,12 @@ # Imports: # - shared/reporting.md # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/daily-issue-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md # - shared/go-source-analysis.md +# - shared/otlp.md # # Secrets used: # - GH_AW_AGENT_TOKEN diff --git a/.github/workflows/stale-repo-identifier.lock.yml b/.github/workflows/stale-repo-identifier.lock.yml index d8dc9593d8f..63a9b8ff6a8 100644 --- a/.github/workflows/stale-repo-identifier.lock.yml +++ b/.github/workflows/stale-repo-identifier.lock.yml @@ -29,11 +29,11 @@ # Imports: # - shared/mcp-pagination.md # - shared/github-guard-policy.md +# - shared/trending-charts-simple.md +# - shared/daily-audit-discussion.md # - ../skills/jqschema/SKILL.md # - shared/otlp.md # - shared/reporting.md -# - shared/trending-charts-simple.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # - shared/daily-audit-charts.md # diff --git a/.github/workflows/terminal-stylist.lock.yml b/.github/workflows/terminal-stylist.lock.yml index 26e481d7bca..9a38d8e80c1 100644 --- a/.github/workflows/terminal-stylist.lock.yml +++ b/.github/workflows/terminal-stylist.lock.yml @@ -27,12 +27,12 @@ # # Resolved workflow manifest: # Imports: -# - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/reporting.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - CODEX_API_KEY diff --git a/.github/workflows/typist.lock.yml b/.github/workflows/typist.lock.yml index e9af110c3a1..c735546e844 100644 --- a/.github/workflows/typist.lock.yml +++ b/.github/workflows/typist.lock.yml @@ -28,11 +28,11 @@ # Resolved workflow manifest: # Imports: # - shared/reporting.md -# - shared/otlp.md # - shared/daily-audit-discussion.md -# - shared/daily-audit-base.md # - shared/mcp/serena.md # - shared/mcp/serena-go.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - ANTHROPIC_API_KEY diff --git a/.github/workflows/ubuntu-image-analyzer.lock.yml b/.github/workflows/ubuntu-image-analyzer.lock.yml index 880f97058d8..edd13d986bf 100644 --- a/.github/workflows/ubuntu-image-analyzer.lock.yml +++ b/.github/workflows/ubuntu-image-analyzer.lock.yml @@ -28,10 +28,10 @@ # Resolved workflow manifest: # Imports: # - shared/skip-if-issue-open.md -# - shared/otlp.md # - shared/activation-app.md # - shared/reporting.md # - shared/daily-pr-base.md +# - shared/otlp.md # # Secrets used: # - COPILOT_GITHUB_TOKEN diff --git a/.github/workflows/uk-ai-operational-resilience.lock.yml b/.github/workflows/uk-ai-operational-resilience.lock.yml index e8805e5461d..c3938ac911c 100644 --- a/.github/workflows/uk-ai-operational-resilience.lock.yml +++ b/.github/workflows/uk-ai-operational-resilience.lock.yml @@ -28,9 +28,9 @@ # Resolved workflow manifest: # Imports: # - shared/mcp-pagination.md +# - shared/daily-audit-discussion.md # - shared/otlp.md # - shared/reporting.md -# - shared/daily-audit-discussion.md # - shared/daily-audit-base.md # # Secrets used: diff --git a/.github/workflows/unbloat-docs.lock.yml b/.github/workflows/unbloat-docs.lock.yml index fc7a15872ca..d2650b4d792 100644 --- a/.github/workflows/unbloat-docs.lock.yml +++ b/.github/workflows/unbloat-docs.lock.yml @@ -27,9 +27,9 @@ # # Resolved workflow manifest: # Imports: +# - shared/activation-app.md # - shared/otlp.md # - shared/reporting.md -# - shared/activation-app.md # - shared/daily-pr-base.md # # Secrets used: diff --git a/.github/workflows/weekly-issue-summary.lock.yml b/.github/workflows/weekly-issue-summary.lock.yml index aba771757ba..ffb5503e123 100644 --- a/.github/workflows/weekly-issue-summary.lock.yml +++ b/.github/workflows/weekly-issue-summary.lock.yml @@ -28,12 +28,12 @@ # Resolved workflow manifest: # Imports: # - shared/github-guard-policy.md -# - shared/otlp.md # - shared/daily-audit-discussion.md # - shared/reporting.md -# - shared/daily-audit-base.md # - shared/python-dataviz.md # - shared/trends.md +# - shared/otlp.md +# - shared/daily-audit-base.md # # Secrets used: # - CODEX_API_KEY From 585f21565d9f7917d5efd23df9023c6eda8645dc Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 2 Sep 2026 00:14:38 +0000 Subject: [PATCH 2/2] Clarify default engine selection guidance Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --- .github/aw/create-agentic-workflow.md | 7 +++++-- .github/aw/designer.md | 14 +++++++++----- .github/aw/syntax-engine.md | 2 +- .github/workflows/craft.lock.yml | 2 +- .github/workflows/craft.md | 5 +++-- 5 files changed, 19 insertions(+), 11 deletions(-) diff --git a/.github/aw/create-agentic-workflow.md b/.github/aw/create-agentic-workflow.md index 80de0ab25a9..3c3cf28c2e1 100644 --- a/.github/aw/create-agentic-workflow.md +++ b/.github/aw/create-agentic-workflow.md @@ -54,14 +54,17 @@ When the request already states a goal, infer its intent and ask only for inform 5. **Data strategy** — ask whether GitHub data should be pre-fetched with `gh` + `jq` (DataOps default); map to `steps:`. 6. **Guardrails** — ask whether it should block, advise, or silently log; guide toward `noop` and safe-output behavior. 7. **Context & network** — ask about external APIs, MCP servers, and required secrets; map to `network.allowed` and `env:`. -8. **Engine** (skip if obvious) — if ambiguous, suggest Copilot as the default. +8. **Engine** — preserve explicit engine hints. With no engine preference or + engine-specific requirement, omit `engine:` and let the configured default + apply. If an explicit model requirement forces engine selection, try Copilot + first. 9. **Confirmation** — present a structured summary before generating: ```text Proposed workflow: - Name: - Trigger: - - Engine: + - Engine: - Tools: - Safe outputs: - Network: diff --git a/.github/aw/designer.md b/.github/aw/designer.md index 960563ea50d..d5a004fc2e4 100644 --- a/.github/aw/designer.md +++ b/.github/aw/designer.md @@ -101,12 +101,16 @@ Map to: ### Phase 7: Engine (optional) -Ask only if ambiguous: **"Any AI engine preference?"** +Ask **"Any AI engine preference?"** only when the request contains ambiguous +engine-specific hints. -If no preference, suggest default: -- "I'd suggest Copilot since you haven't mentioned a preference. Sound good?" +If there is no engine preference or engine-specific requirement, do not suggest +or specify an engine; omit `engine:` and let the configured default apply. If an +explicit model requirement forces engine selection, try Copilot first and select +another engine only when Copilot cannot satisfy that requirement. -Map to `engine:` only when not default. +Map to `engine:` only for an explicit preference or a requirement that the +configured default cannot satisfy. ### Phase 7b: Skills, Plugins, LSP & Evals (optional) @@ -153,7 +157,7 @@ Use this exact structure: 📋 Proposed workflow: - Name: - Trigger: -- Engine: +- Engine: - Tools: - Safe outputs: - Network: diff --git a/.github/aw/syntax-engine.md b/.github/aw/syntax-engine.md index 4c10d7bca05..ab78a461072 100644 --- a/.github/aw/syntax-engine.md +++ b/.github/aw/syntax-engine.md @@ -7,7 +7,7 @@ description: `engine:` frontmatter field detail for GitHub Agentic Workflows. See [syntax-agentic.md](syntax-agentic.md) for the full frontmatter field index. - **`engine:`** - AI processor configuration - - String format: `"copilot"` (default, recommended), `"claude"`, `"codex"`, `"gemini"`, or `"pi"` + - String format: `"copilot"` (current default), `"claude"`, `"codex"`, `"gemini"`, or `"pi"`. Omit `engine:` when there is no engine preference or engine-specific requirement so the configured default remains in effect. If an explicit model requirement forces engine selection, try Copilot first. - The experimental `opencode` engine is available through `imports: [shared/opencode.md]`; see [`smoke-opencode.md`](../workflows/smoke-opencode.md) for an example. - The experimental `deepseek-harness` engine is available through `imports: [shared/deepseek-harness.md]`; see [`smoke-deepseek-harness.md`](../workflows/smoke-deepseek-harness.md) for an example. It runs the developer-preview `dsh` headless profile with AWF provider routing and uses `provider/model` syntax. - The experimental `cursor` engine is available through `imports: [shared/cursor.md]`; see [`smoke-cursor.md`](../workflows/smoke-cursor.md) for an example. Requires the `CURSOR_API_KEY` secret. Cursor reads project rules from `.cursor/rules/*.mdc` and respects the root-level `.cursorignore` and `AGENTS.md`; both are protected in the manifest. Use `model: cursor/auto` or a specific model such as `cursor/claude-3-7-sonnet`. diff --git a/.github/workflows/craft.lock.yml b/.github/workflows/craft.lock.yml index ed322c34e25..f1ce905a803 100644 --- a/.github/workflows/craft.lock.yml +++ b/.github/workflows/craft.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"fef0380d9e8c0c03619ff8425ee5bd4edd019d1dd4a2e9d506bacd96874ade76","body_hash":"586bd821d38db1206ed21e10c9e10c14ea2a82838de1324d81acf4677638858c","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.80","copilot-sdk":"1.0.11"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"fef0380d9e8c0c03619ff8425ee5bd4edd019d1dd4a2e9d506bacd96874ade76","body_hash":"3df14be191add55185d27e3524664e815dca8510c6bcd1623e2ad5138ff69b35","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.80","copilot-sdk":"1.0.11"}} # gh-aw-manifest: {"version":1,"secrets":["GH_AW_CI_TRIGGER_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.28.12","digest":"sha256:390051be4ed1847f774fd8980b61d3a3523574c0175d00c3fc7cdf2002a88202","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.28.12@sha256:390051be4ed1847f774fd8980b61d3a3523574c0175d00c3fc7cdf2002a88202"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.12","digest":"sha256:d7d533d87c80d87ff91ac0e21e9299055c3beedff1536262b97ed700fb065a32","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.12@sha256:d7d533d87c80d87ff91ac0e21e9299055c3beedff1536262b97ed700fb065a32"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.12","digest":"sha256:5250629d48eaedfedf2e948785228e8da29eec2a83cbab58ea0751c14a7b021d","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.12@sha256:5250629d48eaedfedf2e948785228e8da29eec2a83cbab58ea0751c14a7b021d"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.28.12","digest":"sha256:52c34aca98d2a6833c329f1505912a6949c4fda16618c010c979bd59ea99254f","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.28.12@sha256:52c34aca98d2a6833c329f1505912a6949c4fda16618c010c979bd59ea99254f"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.14","digest":"sha256:b2f0c2b2f17b5fbe809e5bb99dc185b6ddd70df25295dc63a6d526350334eff5","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.14@sha256:b2f0c2b2f17b5fbe809e5bb99dc185b6ddd70df25295dc63a6d526350334eff5"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:bac2192f6374d6262116399b34fc5e143d576f82719e90a18261cae7480f4d4e","pinned_image":"ghcr.io/github/gh-aw-node@sha256:bac2192f6374d6262116399b34fc5e143d576f82719e90a18261cae7480f4d4e"},{"image":"ghcr.io/github/github-mcp-server:v1.11.0","digest":"sha256:fbec75de11c255213fa08d80fb166abe73d851fff631c51c0079872967720699","pinned_image":"ghcr.io/github/github-mcp-server:v1.11.0@sha256:fbec75de11c255213fa08d80fb166abe73d851fff631c51c0079872967720699"}],"mcp_servers":[{"name":"safeoutputs","tools":["add_comment","missing_data","missing_tool","noop","push_to_pull_request_branch"]}]} # This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # diff --git a/.github/workflows/craft.md b/.github/workflows/craft.md index 330d8e07bd0..1c993f83124 100644 --- a/.github/workflows/craft.md +++ b/.github/workflows/craft.md @@ -103,7 +103,9 @@ Create a workflow that includes: **Frontmatter (YAML):** - `on:` - Appropriate trigger(s) - `permissions:` - Minimal required permissions -- `engine:` - Default to "copilot" +- `engine:` - Omit when the request gives no engine preference or + engine-specific requirement. If an explicit model requirement forces engine + selection, try Copilot first. - `tools:` - Only include tools that are actually needed - `safe-outputs:` - Configure if the workflow should create issues/PRs/comments/discussions - `timeout-minutes:` - Reasonable timeout (typically 10-15 minutes) @@ -248,7 +250,6 @@ on: permissions: contents: read issues: write -engine: copilot tools: github: mode: gh-proxy