Repository navigation
Tags: github/gh-aw
Tags
Bump gh-aw-firewall to v0.28.49 and gh-aw-mcpg to v0.4.30 (#66924) * Initial plan * Bump firewall and MCP gateway versions Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com> * Merge main into firewall version bump Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com> * Preserve historical gateway and Kreuzberg pins Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com> Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Surface model-routing decisions in logs, audits, and unified sessions (… …#66645) * Initial plan * Add model routing observability to logs and audit Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> * Add draft ADR for client-side model-routing observability * Plan PR review follow-ups Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> * Fix model routing audit and usage regressions Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Peli de Halleux <pelikhan@users.noreply.github.com>
Support Claude Code with GitHub Copilot inference (#66289) * Support Claude inference through GitHub Copilot Infer GitHub inference from copilot-prefixed Claude models, isolate credentials in AWF, and require the reflected Copilot endpoint. Cover main and detection routing, document configuration and CAPI limitations, and add a deterministic native inference and MCP canary. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * docs: add draft ADR-66289 for Claude Copilot inference routing * Address Claude Copilot inference review feedback Normalize CLI model defaults before all Claude retries and share existing provider aliases and secret-skip rules. Harden the CAPI canary with explicit AWF configuration and an unpredictable tool-result nonce, align legacy engine sandbox validation, and correct the proposed routing ADR. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: accept unavailable reflection data in Claude harness Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Render failure diagnostics safely with progressive disclosure (#66292) * fix: safely render failure diagnostics with progressive disclosure Omit raw engine logs and arbitrary log tails from failure reports. Render incomplete signals and extracted engine errors in bounded, redacted code blocks inside collapsed details sections. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: harden diagnostic redaction and normalization Mask exact secrets before pattern redaction, stabilize bounded diagnostics before choosing code fences, and retain recognized engine error summaries without raw log payloads. Add final-comment regressions for nested and control-separated encoded delimiters. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Add dynamic workflow smoke and opt-in engine defaults (#66195) * Add packaged Copilot dynamic workflow smoke test Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Grant reusable smoke caller required conclusion and eval permissions Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Enable experimental Copilot CLI workflow tools in smoke test Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Test native dynamic workflows with Copilot CLI 1.0.92 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Preserve and render Copilot dynamic workflow lifecycle events Keep ephemeral workflow signals and child correlation metadata in SDK logs, project compact lifecycle fields into unified sessions, and cover failures and watchdog activity with regression tests. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Require explicit opt-in for dynamic workflows across engines Default engine.dynamic-workflows to false for every engine and mark enabled Copilot dynamic workflows as experimental during compilation. Keep CLI settings, permissions, SDK capabilities, trusted config restoration, schemas, documentation, and compiled workflows consistent with the shared opt-in default. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * docs(adr): add draft ADR-66195 for opt-in dynamic workflows --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Support dynamic workflows in the Copilot CLI engine (#65937) * feat: support dynamic workflows in the Copilot CLI engine Reuse engine-specific activation artifact restoration, enable targeted extension discovery and workflow permissions, and honor explicit opt-out. Include regression coverage, documentation, and regenerated workflow lock files. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * test: refresh WASM goldens for Copilot dynamic workflows Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * refactor: reuse engine manifest folder restoration for dynamic workflows Remove the dynamic workflow restore provider and dedicated restore steps. Use the existing engine-declared manifest folders and shared activation restore script, preserving PR-only behavior when dynamic workflows are disabled. Refresh workflow locks and WASM goldens. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * test: align Copilot SDK fixture with default workflow permission Update the shared SDK web-fetch contract fixture to include --allow-tool workflow, matching the compiler's default dynamic-workflows configuration without relaxing the contract assertion. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: preserve PR restoration guards and expose SDK workflow tools Keep engine-config restoration gated on successful PR checkout whenever checkout-pr is generated, retaining shared cleanup when the base snapshot is missing. Wire dynamic workflow capabilities, source-qualified SDK tools, and scoped approvals into the compiler-owned SDK contract with managed-policy and opt-out coverage. Regenerate compiled workflows and WASM goldens. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
PreviousNext