chore: recompile agentic workflow lock files#4170
Conversation
Recompile all .lock.yml files and apply post-processing after Azure OpenAI BYOK routing support was added to the branch. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Smoke Test: Claude Engine
Result: PASS
|
🔬 Smoke Test Results
Overall: PASS PR by @lpcox · Reviewer:
|
🔥 Smoke Test: Copilot BYOK (Offline) Mode
Running in BYOK offline mode ( PR: "chore: recompile agentic workflow lock files" by @lpcox | Reviewer: Overall: PARTIAL — BYOK inference and MCP confirmed working; pre-step template outputs (
|
|
Reviewed PRs:\n- fix: recompile all workflow lock files\n- api-proxy: make Anthropic WIF token endpoint configurable via schema-backed config and improve OIDC refresh diagnostics\n\nChecks:\n- Merged PR review: ✅\n- safeinputs-gh query: ❌\n- Playwright title check: ✅\n- File write/read: ✅\n- Discussion lookup/comment: ✅\n- Build: ✅\n\nOverall: PASS Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "registry.npmjs.org"See Network Configuration for more information.
|
Gemini Engine Smoke Test Results\n\n- GitHub MCP Testing: ❌ (mcpscripts command not found)\n- GitHub.com Connectivity: ❌ (HTTP 000 / SSL error 35)\n- File Writing Testing: ✅\n- Bash Tool Testing: ✅\n\nOverall Status: FAILWarning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "localhost"See Network Configuration for more information.
|
There was a problem hiding this comment.
Pull request overview
This PR regenerates agentic workflow lock files and related workflow assets after upstream changes (notably around BYOK routing behavior), updating the pinned action SHAs/container tags and re-emitting the compiled AWF invocations.
Changes:
- Recompiled several
.lock.ymlworkflows, updating gh-aw metadata/manifests, action pins, container image versions, and some generated runtime snippets. - Updated
agentics-maintenance.ymlgeneration output, including the forecast report step contents. - Updated
.github/aw/actions-lock.jsonwith additional pinned action entries.
Show a summary per file
| File | Description |
|---|---|
| .github/workflows/smoke-otel-tracing.lock.yml | Regenerated lock workflow; updates gh-aw metadata, action/container pins, and generated AWF invocation snippets. |
| .github/workflows/smoke-gemini.lock.yml | Regenerated lock workflow; updates gh-aw metadata, action/container pins, and generated AWF invocation snippets. |
| .github/workflows/smoke-copilot.lock.yml | Regenerated lock workflow; updates gh-aw metadata, action/container pins, and generated AWF invocation snippets. |
| .github/workflows/smoke-codex.lock.yml | Regenerated lock workflow; updates pins and runtime env (notably RUST_LOG). |
| .github/workflows/security-review.lock.yml | Regenerated lock workflow; updates gh-aw metadata, action/container pins, and generated AWF invocation snippets. |
| .github/workflows/refactoring-scanner.lock.yml | Regenerated lock workflow; updates gh-aw metadata, action/container pins, and generated AWF invocation snippets. |
| .github/workflows/duplicate-code-detector.lock.yml | Regenerated lock workflow; updates gh-aw metadata, action/container pins, and generated AWF invocation snippets. |
| .github/workflows/copilot-token-usage-analyzer.lock.yml | Regenerated lock workflow; updates gh-aw metadata, action/container pins, and generated AWF invocation snippets. |
| .github/workflows/claude-token-usage-analyzer.lock.yml | Regenerated lock workflow; updates gh-aw metadata, action/container pins, and generated AWF invocation snippets. |
| .github/workflows/agentics-maintenance.yml | Regenerated maintenance workflow; modifies forecast report execution (including timeout behavior). |
| .github/aw/actions-lock.json | Updates pinned action lock entries (including gh-aw action pins). |
Copilot's findings
Tip
Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Comments suppressed due to low confidence (1)
.github/aw/actions-lock.json:92
- This actions lock now only records
github/gh-aw-actions/setup(-cli)@v0.76.1, but the repo’s workflow compilation/validation tests currently assertgithub/gh-aw-actions/setup@v0.77.5is present in compiled lock workflows (scripts/ci/smoke-claude-workflow.test.ts:49-52). If the intended pinned gh-aw actions version is v0.77.5, regenerate this file (and the lock workflows) with that version; otherwise, update the CI expectations/versioning so they match the new pins.
"github/gh-aw-actions/setup-cli@v0.76.1": {
"repo": "github/gh-aw-actions/setup-cli",
"version": "v0.76.1",
"sha": "46d564922b082d0db93244972e8005ea6904ee5f"
},
"github/gh-aw-actions/setup@v0.76.1": {
"repo": "github/gh-aw-actions/setup",
"version": "v0.76.1",
"sha": "46d564922b082d0db93244972e8005ea6904ee5f"
},
- Files reviewed: 34/39 changed files
- Comments generated: 3
| # gh-aw-metadata: {"schema_version":"v3","frontmatter_hash":"88c117a592728f6955d5689c0ce6eca332f75b3dea5d32a368f7bfd2812c5867","compiler_version":"v0.76.1","agent_id":"copilot"} | ||
| # gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/checkout","sha":"de0fac2e4500dabe0009e67214ff5f5447ce83dd","version":"v6.0.2"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"46d564922b082d0db93244972e8005ea6904ee5f","version":"v0.76.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.25.55"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.25.55"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.25.55"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.1","digest":"sha256:287fad0236959f3b3d9936ea1ef8d5b4f135ef2a5f5789713495cbbef191e60c","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.1@sha256:287fad0236959f3b3d9936ea1ef8d5b4f135ef2a5f5789713495cbbef191e60c"},{"image":"ghcr.io/github/github-mcp-server:v1.0.4","digest":"sha256:e3816a476a977cfb836e7d221510011436c654d11861db66ecfd826601aba6a4","pinned_image":"ghcr.io/github/github-mcp-server:v1.0.4@sha256:e3816a476a977cfb836e7d221510011436c654d11861db66ecfd826601aba6a4"},{"image":"node:lts-alpine","digest":"sha256:d1b3b4da11eefd5941e7f0b9cf17783fc99d9c6fc34884a665f40a06dbdfc94f","pinned_image":"node:lts-alpine@sha256:d1b3b4da11eefd5941e7f0b9cf17783fc99d9c6fc34884a665f40a06dbdfc94f"}]} |
| echo "::error::Forecast computation failed with exit code ${forecast_exit_code}." | ||
| exit 1 | ||
| fi | ||
| ${GH_AW_CMD_PREFIX} forecast --repo "${{ github.repository }}" --json 2> >(grep -Fv "forecast is an experimental command and may change without notice" >&2) > ./.cache/gh-aw/forecast/report.json |
| OPENAI_API_KEY: ${{ secrets.CODEX_API_KEY || secrets.OPENAI_API_KEY }} | ||
| RUNNER_TEMP: ${{ runner.temp }} | ||
| RUST_LOG: ${{ runner.debug == 1 && 'trace,hyper_util=info,mio=info,reqwest=info,os_info=info,codex_otel=warn,codex_core=debug,ocodex_exec=debug' || 'warn' }} | ||
| RUST_LOG: trace,hyper_util=info,mio=info,reqwest=info,os_info=info,codex_otel=warn,codex_core=debug,ocodex_exec=debug |
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — ✅ PASS
|
Smoke Test Results — FAIL
Overall: FAIL —
|
Recompiles all
.lock.ymlfiles and applies post-processing after the Azure OpenAI BYOK routing support was merged into the parent branch.Changes
gh aw compilepostprocess-smoke-workflows.tsParent PR: #4162