From 1e603c0706c8a8c7807b8815f5a06f298a2d57b7 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 20 Jul 2026 07:45:06 +0000 Subject: [PATCH 1/7] Initial plan From d69232e4a17e2c8624dbaf3e5e872888d50daae0 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 20 Jul 2026 07:52:27 +0000 Subject: [PATCH 2/7] Plan agent assignment permission guidance cleanup Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --- .../workflows/daily-vulnhunter-scan.lock.yml | 68 +++++++++---------- 1 file changed, 34 insertions(+), 34 deletions(-) diff --git a/.github/workflows/daily-vulnhunter-scan.lock.yml b/.github/workflows/daily-vulnhunter-scan.lock.yml index c0087e92031..e9a6dbcdc81 100644 --- a/.github/workflows/daily-vulnhunter-scan.lock.yml +++ b/.github/workflows/daily-vulnhunter-scan.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"f6b6a6bae81bf07348dc7b4bf8d6b1f1befb67eb7e7a805e238c72712b903d9b","body_hash":"a48dbec98bfea6f55c1ae6e80414c0759b46e692b7c5712b5c122f80dd909fcd","strict":true,"agent_id":"claude","agent_model":"claude-opus-4.6","engine_versions":{"claude":"2.1.210"}} -# gh-aw-manifest: {"version":1,"secrets":["ANTHROPIC_API_KEY","COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.35","digest":"sha256:2202f63e8650b2b8b0d38033b44a05387b2b71ad3e690c4d23a34786f5462aed","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.35@sha256:2202f63e8650b2b8b0d38033b44a05387b2b71ad3e690c4d23a34786f5462aed"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.35","digest":"sha256:755b79d0dfda82bd6b43a208d68666721e504110c5d342a4eeb199802644ff04","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.35@sha256:755b79d0dfda82bd6b43a208d68666721e504110c5d342a4eeb199802644ff04"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.35","digest":"sha256:f69282ec7b1326ba53891c399cf5b10475c0d3ccf4e1519b33d234a5427b57d3","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.35@sha256:f69282ec7b1326ba53891c399cf5b10475c0d3ccf4e1519b33d234a5427b57d3"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"f6b6a6bae81bf07348dc7b4bf8d6b1f1befb67eb7e7a805e238c72712b903d9b","body_hash":"a48dbec98bfea6f55c1ae6e80414c0759b46e692b7c5712b5c122f80dd909fcd","strict":true,"agent_id":"claude","agent_model":"claude-opus-4.6","engine_versions":{"claude":"2.1.214"}} +# gh-aw-manifest: {"version":1,"secrets":["ANTHROPIC_API_KEY","COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37","digest":"sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37","digest":"sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37","digest":"sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.1","digest":"sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.6.0","digest":"sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3","pinned_image":"ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3"}]} # This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -51,9 +51,9 @@ # - actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 # # Container images used: -# - ghcr.io/github/gh-aw-firewall/agent:0.27.35@sha256:2202f63e8650b2b8b0d38033b44a05387b2b71ad3e690c4d23a34786f5462aed -# - ghcr.io/github/gh-aw-firewall/api-proxy:0.27.35@sha256:755b79d0dfda82bd6b43a208d68666721e504110c5d342a4eeb199802644ff04 -# - ghcr.io/github/gh-aw-firewall/squid:0.27.35@sha256:f69282ec7b1326ba53891c399cf5b10475c0d3ccf4e1519b33d234a5427b57d3 +# - ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 +# - ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 +# - ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b # - ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 # - ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b # - ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 @@ -128,8 +128,8 @@ jobs: env: GH_AW_SETUP_WORKFLOW_NAME: "Daily VulnHunter Scan" GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/daily-vulnhunter-scan.lock.yml@${{ github.ref }} - GH_AW_INFO_VERSION: "2.1.210" - GH_AW_INFO_AWF_VERSION: "v0.27.35" + GH_AW_INFO_VERSION: "2.1.214" + GH_AW_INFO_AWF_VERSION: "v0.27.37" GH_AW_INFO_ENGINE_ID: "claude" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" @@ -139,15 +139,15 @@ jobs: GH_AW_INFO_ENGINE_ID: "claude" GH_AW_INFO_ENGINE_NAME: "Claude Code" GH_AW_INFO_MODEL: "claude-opus-4.6" - GH_AW_INFO_VERSION: "2.1.210" - GH_AW_INFO_AGENT_VERSION: "2.1.210" + GH_AW_INFO_VERSION: "2.1.214" + GH_AW_INFO_AGENT_VERSION: "2.1.214" GH_AW_INFO_WORKFLOW_NAME: "Daily VulnHunter Scan" GH_AW_INFO_EXPERIMENTAL: "false" GH_AW_INFO_SUPPORTS_TOOLS_ALLOWLIST: "true" GH_AW_INFO_STAGED: "false" GH_AW_INFO_ALLOWED_DOMAINS: '["*.grafana.net","*.sentry.io","defaults","github"]' GH_AW_INFO_FIREWALL_ENABLED: "true" - GH_AW_INFO_AWF_VERSION: "v0.27.35" + GH_AW_INFO_AWF_VERSION: "v0.27.37" GH_AW_INFO_AWMG_VERSION: "" GH_AW_INFO_FIREWALL_TYPE: "squid" GH_AW_INFO_FRONTMATTER_EMOJI: "🛡️" @@ -456,8 +456,8 @@ jobs: env: GH_AW_SETUP_WORKFLOW_NAME: "Daily VulnHunter Scan" GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/daily-vulnhunter-scan.lock.yml@${{ github.ref }} - GH_AW_INFO_VERSION: "2.1.210" - GH_AW_INFO_AWF_VERSION: "v0.27.35" + GH_AW_INFO_VERSION: "2.1.214" + GH_AW_INFO_AWF_VERSION: "v0.27.37" GH_AW_INFO_ENGINE_ID: "claude" - name: Set runtime paths id: set-runtime-paths @@ -516,9 +516,9 @@ jobs: node-version: '24' package-manager-cache: false - name: Install AWF binary - run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.27.35 --rootless + run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.27.37 --rootless - name: Install Claude Code CLI - run: npm install -g @anthropic-ai/claude-code@2.1.210 + run: npm install -g @anthropic-ai/claude-code@2.1.214 - name: Determine automatic lockdown mode for GitHub MCP Server id: determine-automatic-lockdown uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 (source v9) @@ -545,7 +545,7 @@ jobs: GH_AW_SKILL_DIR: ".claude/skills" run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_inline_skills.sh" - name: Download container images - run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.35@sha256:2202f63e8650b2b8b0d38033b44a05387b2b71ad3e690c4d23a34786f5462aed ghcr.io/github/gh-aw-firewall/api-proxy:0.27.35@sha256:755b79d0dfda82bd6b43a208d68666721e504110c5d342a4eeb199802644ff04 ghcr.io/github/gh-aw-firewall/squid:0.27.35@sha256:f69282ec7b1326ba53891c399cf5b10475c0d3ccf4e1519b33d234a5427b57d3 ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 + run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b ghcr.io/github/gh-aw-mcpg:v0.4.1@sha256:ad2a979c2cd8b50098e84938ca9c9c1580eb8e91526f101a90adfba7859b2c32 ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b ghcr.io/github/github-mcp-server:v1.6.0@sha256:2b0c48b070f61e9d3969269ead600f62d00fb237b60ac849ef3d166ee7de9ad3 - name: Generate Safe Outputs Config run: | mkdir -p "${RUNNER_TEMP}/gh-aw/safeoutputs" @@ -884,7 +884,7 @@ jobs: touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) GH_AW_MAX_AI_CREDITS="${{ vars.GH_AW_DEFAULT_MAX_AI_CREDITS || '1000' }}" - printf '%s\n' "{\"\$schema\":\"https://github.com/github/gh-aw-firewall/releases/download/v0.27.35/awf-config.schema.json\",\"network\":{\"allowDomains\":[\"*.githubusercontent.com\",\"*.grafana.net\",\"*.sentry.io\",\"anthropic.com\",\"api.anthropic.com\",\"api.github.com\",\"api.snapcraft.io\",\"archive.ubuntu.com\",\"azure.archive.ubuntu.com\",\"cdn.playwright.dev\",\"codeload.github.com\",\"crl.geotrust.com\",\"crl.globalsign.com\",\"crl.identrust.com\",\"crl.sectigo.com\",\"crl.thawte.com\",\"crl.usertrust.com\",\"crl.verisign.com\",\"crl3.digicert.com\",\"crl4.digicert.com\",\"crls.ssl.com\",\"docs.github.com\",\"files.pythonhosted.org\",\"ghcr.io\",\"github-cloud.githubusercontent.com\",\"github-cloud.s3.amazonaws.com\",\"github.blog\",\"github.com\",\"github.githubassets.com\",\"host.docker.internal\",\"json-schema.org\",\"json.schemastore.org\",\"keyserver.ubuntu.com\",\"lfs.github.com\",\"objects.githubusercontent.com\",\"ocsp.digicert.com\",\"ocsp.geotrust.com\",\"ocsp.globalsign.com\",\"ocsp.identrust.com\",\"ocsp.sectigo.com\",\"ocsp.ssl.com\",\"ocsp.thawte.com\",\"ocsp.usertrust.com\",\"ocsp.verisign.com\",\"packagecloud.io\",\"packages.cloud.google.com\",\"packages.microsoft.com\",\"patch-diff.githubusercontent.com\",\"patchdiff.githubusercontent.com\",\"playwright.download.prss.microsoft.com\",\"ppa.launchpad.net\",\"pypi.org\",\"raw.githubusercontent.com\",\"registry.npmjs.org\",\"s.symcb.com\",\"s.symcd.com\",\"security.ubuntu.com\",\"sentry.io\",\"statsig.anthropic.com\",\"ts-crl.ws.symantec.com\",\"ts-ocsp.ws.symantec.com\",\"www.googleapis.com\"],\"isolation\":true,\"topologyAttach\":[\"awmg-mcpg\"]},\"apiProxy\":{\"enabled\":true,\"enableTokenSteering\":true,\"maxRuns\":500,\"maxAiCredits\":${GH_AW_MAX_AI_CREDITS},\"maxCacheMisses\":5,\"models\":{\"agent\":[\"sonnet-6x\",\"gpt-5.4\",\"gpt-5.3\",\"gemini-pro\",\"any\"],\"antigravity\":[\"copilot/antigravity*\",\"google/antigravity*\",\"gemini/antigravity*\"],\"any\":[\"copilot/*\",\"anthropic/*\",\"openai/*\",\"google/*\",\"gemini/*\"],\"claude\":[\"agent\"],\"codex\":[\"agent\"],\"coding\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\",\"gpt-5-codex\",\"kimi\"],\"computer-use\":[\"copilot/*computer-use*\",\"google/*computer-use*\",\"gemini/*computer-use*\",\"openai/*computer-use*\"],\"copilot\":[\"agent\"],\"deep-research\":[\"copilot/deep-research*\",\"copilot/o3-deep-research*\",\"copilot/o4-mini-deep-research*\",\"google/deep-research*\",\"gemini/deep-research*\",\"openai/o3-deep-research*\",\"openai/o4-mini-deep-research*\"],\"fable\":[\"copilot/*fable*\",\"anthropic/*fable*\"],\"gemini\":[\"agent\"],\"gemini-3-flash\":[\"copilot/gemini-3*flash*\",\"google/gemini-3*flash*\",\"gemini/gemini-3*flash*\"],\"gemini-3-pro\":[\"copilot/gemini-3*pro*\",\"google/gemini-3*pro*\",\"google/nano-banana*\",\"gemini/gemini-3*pro*\"],\"gemini-3.1-flash\":[\"copilot/gemini-3.1*flash*\",\"google/gemini-3.1*flash*\",\"gemini/gemini-3.1*flash*\"],\"gemini-3.1-pro\":[\"copilot/gemini-3.1*pro*\",\"google/gemini-3.1*pro*\",\"gemini/gemini-3.1*pro*\"],\"gemini-3.5-flash\":[\"copilot/gemini-3.5*flash*\",\"google/gemini-3.5*flash*\",\"gemini/gemini-3.5*flash*\"],\"gemini-flash\":[\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"],\"gemini-flash-lite\":[\"copilot/gemini-*flash*lite*\",\"google/gemini-*flash*lite*\",\"gemini/gemini-*flash*lite*\"],\"gemini-omni\":[\"copilot/gemini-omni*\",\"google/gemini-omni*\",\"gemini/gemini-omni*\"],\"gemini-pro\":[\"copilot/gemini-*pro*\",\"google/gemini-*pro*\",\"gemini/gemini-*pro*\"],\"gemma\":[\"copilot/gemma*\",\"google/gemma*\",\"gemini/gemma*\"],\"gpt-5\":[\"copilot/gpt-5*\",\"openai/gpt-5*\"],\"gpt-5-codex\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\"],\"gpt-5-mini\":[\"copilot/gpt-5*mini*\",\"openai/gpt-5*mini*\"],\"gpt-5-nano\":[\"copilot/gpt-5*nano*\",\"openai/gpt-5*nano*\"],\"gpt-5-pro\":[\"copilot/gpt-5*pro*\",\"openai/gpt-5*pro*\"],\"gpt-5.1\":[\"copilot/gpt-5.1*\",\"openai/gpt-5.1*\"],\"gpt-5.2\":[\"copilot/gpt-5.2*\",\"openai/gpt-5.2*\"],\"gpt-5.3\":[\"copilot/gpt-5.3*\",\"openai/gpt-5.3*\"],\"gpt-5.4\":[\"copilot/gpt-5.4*\",\"openai/gpt-5.4*\"],\"gpt-5.5\":[\"copilot/gpt-5.5*\",\"openai/gpt-5.5*\"],\"gpt-5.6\":[\"copilot/gpt-5.6*\",\"openai/gpt-5.6*\"],\"haiku\":[\"copilot/*haiku*\",\"anthropic/*haiku*\"],\"image-generation\":[\"copilot/gpt-image*\",\"openai/gpt-image*\",\"openai/chatgpt-image*\",\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"google/imagen*\"],\"kimi\":[\"copilot/kimi*\",\"openai/kimi*\"],\"kiwi\":[\"copilot/kiwi*\",\"openai/kiwi*\"],\"large\":[\"fable\",\"sonnet\",\"gpt-5-pro\",\"gpt-5\",\"gemini-pro\"],\"lyria\":[\"google/lyria*\",\"gemini/lyria*\",\"copilot/lyria*\"],\"mai-code\":[\"copilot/MAI-Code*\",\"copilot/mai-code*\",\"openai/MAI-Code*\"],\"mai-code-1-flash-picker\":[\"copilot/MAI-Code-1-Flash-picker*\",\"copilot/mai-code-1-flash-picker*\",\"openai/MAI-Code-1-Flash-picker*\"],\"mini\":[\"haiku\",\"gpt-5-mini\",\"gpt-5-nano\",\"gemini-flash-lite\"],\"nano-banana\":[\"copilot/nano-banana*\",\"google/nano-banana*\",\"gemini/nano-banana*\"],\"opus\":[\"copilot/*opus*\",\"anthropic/*opus*\"],\"opusplan\":[\"opus?effort=high\"],\"reasoning\":[\"copilot/o1*\",\"copilot/o3*\",\"copilot/o4*\",\"openai/o1*\",\"openai/o3*\",\"openai/o4*\"],\"robotics\":[\"copilot/*robotics*\",\"google/*robotics*\",\"gemini/*robotics*\"],\"small\":[\"mini\"],\"small-agent\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash\"],\"sonnet\":[\"copilot/*sonnet*\",\"anthropic/*sonnet*\"],\"sonnet-6x\":[\"copilot/*sonnet-4.5*\",\"copilot/*sonnet-4.6*\",\"copilot/*sonnet-4-5-*\",\"anthropic/*sonnet-4-5-*\",\"copilot/*sonnet-4-6*\",\"anthropic/*sonnet-4-6*\"],\"summarization\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash-lite\",\"mini\"],\"veo\":[\"google/veo*\",\"gemini/veo*\"],\"vision\":[\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"]}},\"container\":{\"imageTag\":\"0.27.35,squid=sha256:f69282ec7b1326ba53891c399cf5b10475c0d3ccf4e1519b33d234a5427b57d3,agent=sha256:2202f63e8650b2b8b0d38033b44a05387b2b71ad3e690c4d23a34786f5462aed,api-proxy=sha256:755b79d0dfda82bd6b43a208d68666721e504110c5d342a4eeb199802644ff04,cli-proxy=sha256:fe83cd274636efa9de3f456e2b078fae137328b9bb6ee4986ae510acaef0cec5\"},\"logging\":{\"proxyLogsDir\":\"/tmp/gh-aw/sandbox/firewall/logs\",\"auditDir\":\"/tmp/gh-aw/sandbox/firewall/audit\"}}" > "${RUNNER_TEMP}/gh-aw/awf-config.json" + printf '%s\n' "{\"\$schema\":\"https://github.com/github/gh-aw-firewall/releases/download/v0.27.37/awf-config.schema.json\",\"network\":{\"allowDomains\":[\"*.githubusercontent.com\",\"*.grafana.net\",\"*.sentry.io\",\"anthropic.com\",\"api.anthropic.com\",\"api.github.com\",\"api.snapcraft.io\",\"archive.ubuntu.com\",\"azure.archive.ubuntu.com\",\"cdn.playwright.dev\",\"codeload.github.com\",\"crl.geotrust.com\",\"crl.globalsign.com\",\"crl.identrust.com\",\"crl.sectigo.com\",\"crl.thawte.com\",\"crl.usertrust.com\",\"crl.verisign.com\",\"crl3.digicert.com\",\"crl4.digicert.com\",\"crls.ssl.com\",\"docs.github.com\",\"files.pythonhosted.org\",\"ghcr.io\",\"github-cloud.githubusercontent.com\",\"github-cloud.s3.amazonaws.com\",\"github.blog\",\"github.com\",\"github.githubassets.com\",\"host.docker.internal\",\"json-schema.org\",\"json.schemastore.org\",\"keyserver.ubuntu.com\",\"lfs.github.com\",\"objects.githubusercontent.com\",\"ocsp.digicert.com\",\"ocsp.geotrust.com\",\"ocsp.globalsign.com\",\"ocsp.identrust.com\",\"ocsp.sectigo.com\",\"ocsp.ssl.com\",\"ocsp.thawte.com\",\"ocsp.usertrust.com\",\"ocsp.verisign.com\",\"packagecloud.io\",\"packages.cloud.google.com\",\"packages.microsoft.com\",\"patch-diff.githubusercontent.com\",\"patchdiff.githubusercontent.com\",\"playwright.download.prss.microsoft.com\",\"ppa.launchpad.net\",\"pypi.org\",\"raw.githubusercontent.com\",\"registry.npmjs.org\",\"s.symcb.com\",\"s.symcd.com\",\"security.ubuntu.com\",\"sentry.io\",\"statsig.anthropic.com\",\"ts-crl.ws.symantec.com\",\"ts-ocsp.ws.symantec.com\",\"www.googleapis.com\"],\"isolation\":true,\"topologyAttach\":[\"awmg-mcpg\"]},\"apiProxy\":{\"enabled\":true,\"enableTokenSteering\":true,\"maxRuns\":500,\"maxAiCredits\":${GH_AW_MAX_AI_CREDITS},\"maxCacheMisses\":5,\"models\":{\"agent\":[\"sonnet-6x\",\"gpt-5.4\",\"gpt-5.3\",\"gemini-pro\",\"any\"],\"antigravity\":[\"copilot/antigravity*\",\"google/antigravity*\",\"gemini/antigravity*\"],\"any\":[\"copilot/*\",\"anthropic/*\",\"openai/*\",\"google/*\",\"gemini/*\"],\"claude\":[\"agent\"],\"codex\":[\"agent\"],\"coding\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\",\"gpt-5-codex\",\"kimi\"],\"computer-use\":[\"copilot/*computer-use*\",\"google/*computer-use*\",\"gemini/*computer-use*\",\"openai/*computer-use*\"],\"copilot\":[\"agent\"],\"deep-research\":[\"copilot/deep-research*\",\"copilot/o3-deep-research*\",\"copilot/o4-mini-deep-research*\",\"google/deep-research*\",\"gemini/deep-research*\",\"openai/o3-deep-research*\",\"openai/o4-mini-deep-research*\"],\"fable\":[\"copilot/*fable*\",\"anthropic/*fable*\"],\"gemini\":[\"agent\"],\"gemini-3-flash\":[\"copilot/gemini-3*flash*\",\"google/gemini-3*flash*\",\"gemini/gemini-3*flash*\"],\"gemini-3-pro\":[\"copilot/gemini-3*pro*\",\"google/gemini-3*pro*\",\"google/nano-banana*\",\"gemini/gemini-3*pro*\"],\"gemini-3.1-flash\":[\"copilot/gemini-3.1*flash*\",\"google/gemini-3.1*flash*\",\"gemini/gemini-3.1*flash*\"],\"gemini-3.1-pro\":[\"copilot/gemini-3.1*pro*\",\"google/gemini-3.1*pro*\",\"gemini/gemini-3.1*pro*\"],\"gemini-3.5-flash\":[\"copilot/gemini-3.5*flash*\",\"google/gemini-3.5*flash*\",\"gemini/gemini-3.5*flash*\"],\"gemini-flash\":[\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"],\"gemini-flash-lite\":[\"copilot/gemini-*flash*lite*\",\"google/gemini-*flash*lite*\",\"gemini/gemini-*flash*lite*\"],\"gemini-omni\":[\"copilot/gemini-omni*\",\"google/gemini-omni*\",\"gemini/gemini-omni*\"],\"gemini-pro\":[\"copilot/gemini-*pro*\",\"google/gemini-*pro*\",\"gemini/gemini-*pro*\"],\"gemma\":[\"copilot/gemma*\",\"google/gemma*\",\"gemini/gemma*\"],\"gpt-5\":[\"copilot/gpt-5*\",\"openai/gpt-5*\"],\"gpt-5-codex\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\"],\"gpt-5-mini\":[\"copilot/gpt-5*mini*\",\"openai/gpt-5*mini*\"],\"gpt-5-nano\":[\"copilot/gpt-5*nano*\",\"openai/gpt-5*nano*\"],\"gpt-5-pro\":[\"copilot/gpt-5*pro*\",\"openai/gpt-5*pro*\"],\"gpt-5.1\":[\"copilot/gpt-5.1*\",\"openai/gpt-5.1*\"],\"gpt-5.2\":[\"copilot/gpt-5.2*\",\"openai/gpt-5.2*\"],\"gpt-5.3\":[\"copilot/gpt-5.3*\",\"openai/gpt-5.3*\"],\"gpt-5.4\":[\"copilot/gpt-5.4*\",\"openai/gpt-5.4*\"],\"gpt-5.5\":[\"copilot/gpt-5.5*\",\"openai/gpt-5.5*\"],\"gpt-5.6\":[\"copilot/gpt-5.6*\",\"openai/gpt-5.6*\"],\"haiku\":[\"copilot/*haiku*\",\"anthropic/*haiku*\"],\"image-generation\":[\"copilot/gpt-image*\",\"openai/gpt-image*\",\"openai/chatgpt-image*\",\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"google/imagen*\"],\"kimi\":[\"copilot/kimi*\",\"openai/kimi*\"],\"kiwi\":[\"copilot/kiwi*\",\"openai/kiwi*\"],\"large\":[\"fable\",\"sonnet\",\"gpt-5-pro\",\"gpt-5\",\"gemini-pro\"],\"lyria\":[\"google/lyria*\",\"gemini/lyria*\",\"copilot/lyria*\"],\"mai-code\":[\"copilot/MAI-Code*\",\"copilot/mai-code*\",\"openai/MAI-Code*\"],\"mai-code-1-flash-picker\":[\"copilot/MAI-Code-1-Flash-picker*\",\"copilot/mai-code-1-flash-picker*\",\"openai/MAI-Code-1-Flash-picker*\"],\"mini\":[\"haiku\",\"gpt-5-mini\",\"gpt-5-nano\",\"gemini-flash-lite\"],\"nano-banana\":[\"copilot/nano-banana*\",\"google/nano-banana*\",\"gemini/nano-banana*\"],\"opus\":[\"copilot/*opus*\",\"anthropic/*opus*\"],\"opusplan\":[\"opus?effort=high\"],\"reasoning\":[\"copilot/o1*\",\"copilot/o3*\",\"copilot/o4*\",\"openai/o1*\",\"openai/o3*\",\"openai/o4*\"],\"robotics\":[\"copilot/*robotics*\",\"google/*robotics*\",\"gemini/*robotics*\"],\"small\":[\"mini\"],\"small-agent\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash\"],\"sonnet\":[\"copilot/*sonnet*\",\"anthropic/*sonnet*\"],\"sonnet-6x\":[\"copilot/*sonnet-4.5*\",\"copilot/*sonnet-4.6*\",\"copilot/*sonnet-4-5-*\",\"anthropic/*sonnet-4-5-*\",\"copilot/*sonnet-4-6*\",\"anthropic/*sonnet-4-6*\"],\"summarization\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash-lite\",\"mini\"],\"veo\":[\"google/veo*\",\"gemini/veo*\"],\"vision\":[\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"]}},\"container\":{\"imageTag\":\"0.27.37,squid=sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b,agent=sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67,api-proxy=sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317,cli-proxy=sha256:1d5300d9b08e1c4f2ad1830860656a0656383a83280058f17e805a7c3ecda203\"},\"logging\":{\"proxyLogsDir\":\"/tmp/gh-aw/sandbox/firewall/logs\",\"auditDir\":\"/tmp/gh-aw/sandbox/firewall/audit\"}}" > "${RUNNER_TEMP}/gh-aw/awf-config.json" cp "${RUNNER_TEMP}/gh-aw/awf-config.json" /tmp/gh-aw/awf-config.json export GH_AW_MODELS_JSON_PATH="/tmp/gh-aw/models.json" GH_AW_DOCKER_HOST="" @@ -1128,8 +1128,8 @@ jobs: env: GH_AW_SETUP_WORKFLOW_NAME: "Daily VulnHunter Scan" GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/daily-vulnhunter-scan.lock.yml@${{ github.ref }} - GH_AW_INFO_VERSION: "2.1.210" - GH_AW_INFO_AWF_VERSION: "v0.27.35" + GH_AW_INFO_VERSION: "2.1.214" + GH_AW_INFO_AWF_VERSION: "v0.27.37" GH_AW_INFO_ENGINE_ID: "claude" - name: Download agent output artifact id: download-agent-output @@ -1395,8 +1395,8 @@ jobs: env: GH_AW_SETUP_WORKFLOW_NAME: "Daily VulnHunter Scan" GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/daily-vulnhunter-scan.lock.yml@${{ github.ref }} - GH_AW_INFO_VERSION: "2.1.210" - GH_AW_INFO_AWF_VERSION: "v0.27.35" + GH_AW_INFO_VERSION: "2.1.214" + GH_AW_INFO_AWF_VERSION: "v0.27.37" GH_AW_INFO_ENGINE_ID: "claude" - name: Download agent output artifact id: download-agent-output @@ -1423,7 +1423,7 @@ jobs: rm -rf /tmp/gh-aw/sandbox/firewall/logs rm -rf /tmp/gh-aw/sandbox/firewall/audit - name: Download container images - run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.35@sha256:2202f63e8650b2b8b0d38033b44a05387b2b71ad3e690c4d23a34786f5462aed ghcr.io/github/gh-aw-firewall/api-proxy:0.27.35@sha256:755b79d0dfda82bd6b43a208d68666721e504110c5d342a4eeb199802644ff04 ghcr.io/github/gh-aw-firewall/squid:0.27.35@sha256:f69282ec7b1326ba53891c399cf5b10475c0d3ccf4e1519b33d234a5427b57d3 + run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b - name: Check if detection needed id: detection_guard if: always() @@ -1486,9 +1486,9 @@ jobs: node-version: '24' package-manager-cache: false - name: Install AWF binary - run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.27.35 + run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.27.37 - name: Install Claude Code CLI - run: npm install -g @anthropic-ai/claude-code@2.1.210 + run: npm install -g @anthropic-ai/claude-code@2.1.214 - name: Execute Claude Code CLI if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true @@ -1516,7 +1516,7 @@ jobs: touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) GH_AW_MAX_AI_CREDITS="${{ vars.GH_AW_DEFAULT_DETECTION_MAX_AI_CREDITS || '400' }}" - printf '%s\n' "{\"\$schema\":\"https://github.com/github/gh-aw-firewall/releases/download/v0.27.35/awf-config.schema.json\",\"network\":{\"allowDomains\":[\"*.githubusercontent.com\",\"anthropic.com\",\"api.anthropic.com\",\"api.github.com\",\"api.snapcraft.io\",\"archive.ubuntu.com\",\"azure.archive.ubuntu.com\",\"cdn.playwright.dev\",\"codeload.github.com\",\"crl.geotrust.com\",\"crl.globalsign.com\",\"crl.identrust.com\",\"crl.sectigo.com\",\"crl.thawte.com\",\"crl.usertrust.com\",\"crl.verisign.com\",\"crl3.digicert.com\",\"crl4.digicert.com\",\"crls.ssl.com\",\"files.pythonhosted.org\",\"ghcr.io\",\"github-cloud.githubusercontent.com\",\"github-cloud.s3.amazonaws.com\",\"github.com\",\"host.docker.internal\",\"json-schema.org\",\"json.schemastore.org\",\"keyserver.ubuntu.com\",\"lfs.github.com\",\"objects.githubusercontent.com\",\"ocsp.digicert.com\",\"ocsp.geotrust.com\",\"ocsp.globalsign.com\",\"ocsp.identrust.com\",\"ocsp.sectigo.com\",\"ocsp.ssl.com\",\"ocsp.thawte.com\",\"ocsp.usertrust.com\",\"ocsp.verisign.com\",\"packagecloud.io\",\"packages.cloud.google.com\",\"packages.microsoft.com\",\"playwright.download.prss.microsoft.com\",\"ppa.launchpad.net\",\"pypi.org\",\"raw.githubusercontent.com\",\"registry.npmjs.org\",\"s.symcb.com\",\"s.symcd.com\",\"security.ubuntu.com\",\"sentry.io\",\"statsig.anthropic.com\",\"ts-crl.ws.symantec.com\",\"ts-ocsp.ws.symantec.com\"]},\"apiProxy\":{\"enabled\":true,\"enableTokenSteering\":true,\"maxRuns\":500,\"maxAiCredits\":${GH_AW_MAX_AI_CREDITS},\"maxCacheMisses\":5,\"models\":{\"agent\":[\"sonnet-6x\",\"gpt-5.4\",\"gpt-5.3\",\"gemini-pro\",\"any\"],\"antigravity\":[\"copilot/antigravity*\",\"google/antigravity*\",\"gemini/antigravity*\"],\"any\":[\"copilot/*\",\"anthropic/*\",\"openai/*\",\"google/*\",\"gemini/*\"],\"claude\":[\"agent\"],\"codex\":[\"agent\"],\"coding\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\",\"gpt-5-codex\",\"kimi\"],\"computer-use\":[\"copilot/*computer-use*\",\"google/*computer-use*\",\"gemini/*computer-use*\",\"openai/*computer-use*\"],\"copilot\":[\"agent\"],\"deep-research\":[\"copilot/deep-research*\",\"copilot/o3-deep-research*\",\"copilot/o4-mini-deep-research*\",\"google/deep-research*\",\"gemini/deep-research*\",\"openai/o3-deep-research*\",\"openai/o4-mini-deep-research*\"],\"fable\":[\"copilot/*fable*\",\"anthropic/*fable*\"],\"gemini\":[\"agent\"],\"gemini-3-flash\":[\"copilot/gemini-3*flash*\",\"google/gemini-3*flash*\",\"gemini/gemini-3*flash*\"],\"gemini-3-pro\":[\"copilot/gemini-3*pro*\",\"google/gemini-3*pro*\",\"google/nano-banana*\",\"gemini/gemini-3*pro*\"],\"gemini-3.1-flash\":[\"copilot/gemini-3.1*flash*\",\"google/gemini-3.1*flash*\",\"gemini/gemini-3.1*flash*\"],\"gemini-3.1-pro\":[\"copilot/gemini-3.1*pro*\",\"google/gemini-3.1*pro*\",\"gemini/gemini-3.1*pro*\"],\"gemini-3.5-flash\":[\"copilot/gemini-3.5*flash*\",\"google/gemini-3.5*flash*\",\"gemini/gemini-3.5*flash*\"],\"gemini-flash\":[\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"],\"gemini-flash-lite\":[\"copilot/gemini-*flash*lite*\",\"google/gemini-*flash*lite*\",\"gemini/gemini-*flash*lite*\"],\"gemini-omni\":[\"copilot/gemini-omni*\",\"google/gemini-omni*\",\"gemini/gemini-omni*\"],\"gemini-pro\":[\"copilot/gemini-*pro*\",\"google/gemini-*pro*\",\"gemini/gemini-*pro*\"],\"gemma\":[\"copilot/gemma*\",\"google/gemma*\",\"gemini/gemma*\"],\"gpt-5\":[\"copilot/gpt-5*\",\"openai/gpt-5*\"],\"gpt-5-codex\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\"],\"gpt-5-mini\":[\"copilot/gpt-5*mini*\",\"openai/gpt-5*mini*\"],\"gpt-5-nano\":[\"copilot/gpt-5*nano*\",\"openai/gpt-5*nano*\"],\"gpt-5-pro\":[\"copilot/gpt-5*pro*\",\"openai/gpt-5*pro*\"],\"gpt-5.1\":[\"copilot/gpt-5.1*\",\"openai/gpt-5.1*\"],\"gpt-5.2\":[\"copilot/gpt-5.2*\",\"openai/gpt-5.2*\"],\"gpt-5.3\":[\"copilot/gpt-5.3*\",\"openai/gpt-5.3*\"],\"gpt-5.4\":[\"copilot/gpt-5.4*\",\"openai/gpt-5.4*\"],\"gpt-5.5\":[\"copilot/gpt-5.5*\",\"openai/gpt-5.5*\"],\"gpt-5.6\":[\"copilot/gpt-5.6*\",\"openai/gpt-5.6*\"],\"haiku\":[\"copilot/*haiku*\",\"anthropic/*haiku*\"],\"image-generation\":[\"copilot/gpt-image*\",\"openai/gpt-image*\",\"openai/chatgpt-image*\",\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"google/imagen*\"],\"kimi\":[\"copilot/kimi*\",\"openai/kimi*\"],\"kiwi\":[\"copilot/kiwi*\",\"openai/kiwi*\"],\"large\":[\"fable\",\"sonnet\",\"gpt-5-pro\",\"gpt-5\",\"gemini-pro\"],\"lyria\":[\"google/lyria*\",\"gemini/lyria*\",\"copilot/lyria*\"],\"mai-code\":[\"copilot/MAI-Code*\",\"copilot/mai-code*\",\"openai/MAI-Code*\"],\"mai-code-1-flash-picker\":[\"copilot/MAI-Code-1-Flash-picker*\",\"copilot/mai-code-1-flash-picker*\",\"openai/MAI-Code-1-Flash-picker*\"],\"mini\":[\"haiku\",\"gpt-5-mini\",\"gpt-5-nano\",\"gemini-flash-lite\"],\"nano-banana\":[\"copilot/nano-banana*\",\"google/nano-banana*\",\"gemini/nano-banana*\"],\"opus\":[\"copilot/*opus*\",\"anthropic/*opus*\"],\"opusplan\":[\"opus?effort=high\"],\"reasoning\":[\"copilot/o1*\",\"copilot/o3*\",\"copilot/o4*\",\"openai/o1*\",\"openai/o3*\",\"openai/o4*\"],\"robotics\":[\"copilot/*robotics*\",\"google/*robotics*\",\"gemini/*robotics*\"],\"small\":[\"mini\"],\"small-agent\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash\"],\"sonnet\":[\"copilot/*sonnet*\",\"anthropic/*sonnet*\"],\"sonnet-6x\":[\"copilot/*sonnet-4.5*\",\"copilot/*sonnet-4.6*\",\"copilot/*sonnet-4-5-*\",\"anthropic/*sonnet-4-5-*\",\"copilot/*sonnet-4-6*\",\"anthropic/*sonnet-4-6*\"],\"summarization\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash-lite\",\"mini\"],\"veo\":[\"google/veo*\",\"gemini/veo*\"],\"vision\":[\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"]}},\"container\":{\"imageTag\":\"0.27.35,squid=sha256:f69282ec7b1326ba53891c399cf5b10475c0d3ccf4e1519b33d234a5427b57d3,agent=sha256:2202f63e8650b2b8b0d38033b44a05387b2b71ad3e690c4d23a34786f5462aed,api-proxy=sha256:755b79d0dfda82bd6b43a208d68666721e504110c5d342a4eeb199802644ff04,cli-proxy=sha256:fe83cd274636efa9de3f456e2b078fae137328b9bb6ee4986ae510acaef0cec5\"},\"logging\":{\"proxyLogsDir\":\"/tmp/gh-aw/sandbox/firewall/logs\",\"auditDir\":\"/tmp/gh-aw/sandbox/firewall/audit\"}}" > "${RUNNER_TEMP}/gh-aw/awf-config.json" + printf '%s\n' "{\"\$schema\":\"https://github.com/github/gh-aw-firewall/releases/download/v0.27.37/awf-config.schema.json\",\"network\":{\"allowDomains\":[\"*.githubusercontent.com\",\"anthropic.com\",\"api.anthropic.com\",\"api.github.com\",\"api.snapcraft.io\",\"archive.ubuntu.com\",\"azure.archive.ubuntu.com\",\"cdn.playwright.dev\",\"codeload.github.com\",\"crl.geotrust.com\",\"crl.globalsign.com\",\"crl.identrust.com\",\"crl.sectigo.com\",\"crl.thawte.com\",\"crl.usertrust.com\",\"crl.verisign.com\",\"crl3.digicert.com\",\"crl4.digicert.com\",\"crls.ssl.com\",\"files.pythonhosted.org\",\"ghcr.io\",\"github-cloud.githubusercontent.com\",\"github-cloud.s3.amazonaws.com\",\"github.com\",\"host.docker.internal\",\"json-schema.org\",\"json.schemastore.org\",\"keyserver.ubuntu.com\",\"lfs.github.com\",\"objects.githubusercontent.com\",\"ocsp.digicert.com\",\"ocsp.geotrust.com\",\"ocsp.globalsign.com\",\"ocsp.identrust.com\",\"ocsp.sectigo.com\",\"ocsp.ssl.com\",\"ocsp.thawte.com\",\"ocsp.usertrust.com\",\"ocsp.verisign.com\",\"packagecloud.io\",\"packages.cloud.google.com\",\"packages.microsoft.com\",\"playwright.download.prss.microsoft.com\",\"ppa.launchpad.net\",\"pypi.org\",\"raw.githubusercontent.com\",\"registry.npmjs.org\",\"s.symcb.com\",\"s.symcd.com\",\"security.ubuntu.com\",\"sentry.io\",\"statsig.anthropic.com\",\"ts-crl.ws.symantec.com\",\"ts-ocsp.ws.symantec.com\"]},\"apiProxy\":{\"enabled\":true,\"enableTokenSteering\":true,\"maxRuns\":500,\"maxAiCredits\":${GH_AW_MAX_AI_CREDITS},\"maxCacheMisses\":5,\"models\":{\"agent\":[\"sonnet-6x\",\"gpt-5.4\",\"gpt-5.3\",\"gemini-pro\",\"any\"],\"antigravity\":[\"copilot/antigravity*\",\"google/antigravity*\",\"gemini/antigravity*\"],\"any\":[\"copilot/*\",\"anthropic/*\",\"openai/*\",\"google/*\",\"gemini/*\"],\"claude\":[\"agent\"],\"codex\":[\"agent\"],\"coding\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\",\"gpt-5-codex\",\"kimi\"],\"computer-use\":[\"copilot/*computer-use*\",\"google/*computer-use*\",\"gemini/*computer-use*\",\"openai/*computer-use*\"],\"copilot\":[\"agent\"],\"deep-research\":[\"copilot/deep-research*\",\"copilot/o3-deep-research*\",\"copilot/o4-mini-deep-research*\",\"google/deep-research*\",\"gemini/deep-research*\",\"openai/o3-deep-research*\",\"openai/o4-mini-deep-research*\"],\"fable\":[\"copilot/*fable*\",\"anthropic/*fable*\"],\"gemini\":[\"agent\"],\"gemini-3-flash\":[\"copilot/gemini-3*flash*\",\"google/gemini-3*flash*\",\"gemini/gemini-3*flash*\"],\"gemini-3-pro\":[\"copilot/gemini-3*pro*\",\"google/gemini-3*pro*\",\"google/nano-banana*\",\"gemini/gemini-3*pro*\"],\"gemini-3.1-flash\":[\"copilot/gemini-3.1*flash*\",\"google/gemini-3.1*flash*\",\"gemini/gemini-3.1*flash*\"],\"gemini-3.1-pro\":[\"copilot/gemini-3.1*pro*\",\"google/gemini-3.1*pro*\",\"gemini/gemini-3.1*pro*\"],\"gemini-3.5-flash\":[\"copilot/gemini-3.5*flash*\",\"google/gemini-3.5*flash*\",\"gemini/gemini-3.5*flash*\"],\"gemini-flash\":[\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"],\"gemini-flash-lite\":[\"copilot/gemini-*flash*lite*\",\"google/gemini-*flash*lite*\",\"gemini/gemini-*flash*lite*\"],\"gemini-omni\":[\"copilot/gemini-omni*\",\"google/gemini-omni*\",\"gemini/gemini-omni*\"],\"gemini-pro\":[\"copilot/gemini-*pro*\",\"google/gemini-*pro*\",\"gemini/gemini-*pro*\"],\"gemma\":[\"copilot/gemma*\",\"google/gemma*\",\"gemini/gemma*\"],\"gpt-5\":[\"copilot/gpt-5*\",\"openai/gpt-5*\"],\"gpt-5-codex\":[\"copilot/gpt-5*codex*\",\"openai/gpt-5*codex*\"],\"gpt-5-mini\":[\"copilot/gpt-5*mini*\",\"openai/gpt-5*mini*\"],\"gpt-5-nano\":[\"copilot/gpt-5*nano*\",\"openai/gpt-5*nano*\"],\"gpt-5-pro\":[\"copilot/gpt-5*pro*\",\"openai/gpt-5*pro*\"],\"gpt-5.1\":[\"copilot/gpt-5.1*\",\"openai/gpt-5.1*\"],\"gpt-5.2\":[\"copilot/gpt-5.2*\",\"openai/gpt-5.2*\"],\"gpt-5.3\":[\"copilot/gpt-5.3*\",\"openai/gpt-5.3*\"],\"gpt-5.4\":[\"copilot/gpt-5.4*\",\"openai/gpt-5.4*\"],\"gpt-5.5\":[\"copilot/gpt-5.5*\",\"openai/gpt-5.5*\"],\"gpt-5.6\":[\"copilot/gpt-5.6*\",\"openai/gpt-5.6*\"],\"haiku\":[\"copilot/*haiku*\",\"anthropic/*haiku*\"],\"image-generation\":[\"copilot/gpt-image*\",\"openai/gpt-image*\",\"openai/chatgpt-image*\",\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"google/imagen*\"],\"kimi\":[\"copilot/kimi*\",\"openai/kimi*\"],\"kiwi\":[\"copilot/kiwi*\",\"openai/kiwi*\"],\"large\":[\"fable\",\"sonnet\",\"gpt-5-pro\",\"gpt-5\",\"gemini-pro\"],\"lyria\":[\"google/lyria*\",\"gemini/lyria*\",\"copilot/lyria*\"],\"mai-code\":[\"copilot/MAI-Code*\",\"copilot/mai-code*\",\"openai/MAI-Code*\"],\"mai-code-1-flash-picker\":[\"copilot/MAI-Code-1-Flash-picker*\",\"copilot/mai-code-1-flash-picker*\",\"openai/MAI-Code-1-Flash-picker*\"],\"mini\":[\"haiku\",\"gpt-5-mini\",\"gpt-5-nano\",\"gemini-flash-lite\"],\"nano-banana\":[\"copilot/nano-banana*\",\"google/nano-banana*\",\"gemini/nano-banana*\"],\"opus\":[\"copilot/*opus*\",\"anthropic/*opus*\"],\"opusplan\":[\"opus?effort=high\"],\"reasoning\":[\"copilot/o1*\",\"copilot/o3*\",\"copilot/o4*\",\"openai/o1*\",\"openai/o3*\",\"openai/o4*\"],\"robotics\":[\"copilot/*robotics*\",\"google/*robotics*\",\"gemini/*robotics*\"],\"small\":[\"mini\"],\"small-agent\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash\"],\"sonnet\":[\"copilot/*sonnet*\",\"anthropic/*sonnet*\"],\"sonnet-6x\":[\"copilot/*sonnet-4.5*\",\"copilot/*sonnet-4.6*\",\"copilot/*sonnet-4-5-*\",\"anthropic/*sonnet-4-5-*\",\"copilot/*sonnet-4-6*\",\"anthropic/*sonnet-4-6*\"],\"summarization\":[\"haiku\",\"gpt-5-mini\",\"gemini-flash-lite\",\"mini\"],\"veo\":[\"google/veo*\",\"gemini/veo*\"],\"vision\":[\"copilot/gemini-*image*\",\"google/gemini-*image*\",\"gemini/gemini-*image*\",\"copilot/gemini-*flash*\",\"google/gemini-*flash*\",\"gemini/gemini-*flash*\"]}},\"container\":{\"imageTag\":\"0.27.37,squid=sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b,agent=sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67,api-proxy=sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317,cli-proxy=sha256:1d5300d9b08e1c4f2ad1830860656a0656383a83280058f17e805a7c3ecda203\"},\"logging\":{\"proxyLogsDir\":\"/tmp/gh-aw/sandbox/firewall/logs\",\"auditDir\":\"/tmp/gh-aw/sandbox/firewall/audit\"}}" > "${RUNNER_TEMP}/gh-aw/awf-config.json" cp "${RUNNER_TEMP}/gh-aw/awf-config.json" /tmp/gh-aw/awf-config.json export GH_AW_MODELS_JSON_PATH="/tmp/gh-aw/models.json" GH_AW_DOCKER_HOST="" @@ -1647,8 +1647,8 @@ jobs: env: GH_AW_SETUP_WORKFLOW_NAME: "Daily VulnHunter Scan" GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/daily-vulnhunter-scan.lock.yml@${{ github.ref }} - GH_AW_INFO_VERSION: "2.1.210" - GH_AW_INFO_AWF_VERSION: "v0.27.35" + GH_AW_INFO_VERSION: "2.1.214" + GH_AW_INFO_AWF_VERSION: "v0.27.37" GH_AW_INFO_ENGINE_ID: "claude" - name: Download agent output artifact id: download-agent-output @@ -1670,7 +1670,7 @@ jobs: rm -rf /tmp/gh-aw/sandbox/firewall/logs rm -rf /tmp/gh-aw/sandbox/firewall/audit - name: Download container images - run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.35@sha256:2202f63e8650b2b8b0d38033b44a05387b2b71ad3e690c4d23a34786f5462aed ghcr.io/github/gh-aw-firewall/api-proxy:0.27.35@sha256:755b79d0dfda82bd6b43a208d68666721e504110c5d342a4eeb199802644ff04 ghcr.io/github/gh-aw-firewall/squid:0.27.35@sha256:f69282ec7b1326ba53891c399cf5b10475c0d3ccf4e1519b33d234a5427b57d3 + run: bash "${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh" ghcr.io/github/gh-aw-firewall/agent:0.27.37@sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67 ghcr.io/github/gh-aw-firewall/api-proxy:0.27.37@sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317 ghcr.io/github/gh-aw-firewall/squid:0.27.37@sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b - name: Prepare evals files run: | mkdir -p /tmp/gh-aw/evals @@ -1700,9 +1700,9 @@ jobs: node-version: '24' package-manager-cache: false - name: Install AWF binary - run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.27.35 + run: bash "${RUNNER_TEMP}/gh-aw/actions/install_awf_binary.sh" v0.27.37 - name: Install Claude Code CLI - run: npm install -g @anthropic-ai/claude-code@2.1.210 + run: npm install -g @anthropic-ai/claude-code@2.1.214 - name: Execute Claude Code CLI if: always() continue-on-error: true @@ -1730,7 +1730,7 @@ jobs: touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/evals/evals.log) GH_AW_MAX_AI_CREDITS="${{ vars.GH_AW_DEFAULT_DETECTION_MAX_AI_CREDITS || '400' }}" - printf '%s\n' "{\"\$schema\":\"https://github.com/github/gh-aw-firewall/releases/download/v0.27.35/awf-config.schema.json\",\"network\":{\"allowDomains\":[\"*.githubusercontent.com\",\"anthropic.com\",\"api.anthropic.com\",\"api.github.com\",\"api.snapcraft.io\",\"archive.ubuntu.com\",\"azure.archive.ubuntu.com\",\"cdn.playwright.dev\",\"codeload.github.com\",\"crl.geotrust.com\",\"crl.globalsign.com\",\"crl.identrust.com\",\"crl.sectigo.com\",\"crl.thawte.com\",\"crl.usertrust.com\",\"crl.verisign.com\",\"crl3.digicert.com\",\"crl4.digicert.com\",\"crls.ssl.com\",\"files.pythonhosted.org\",\"ghcr.io\",\"github-cloud.githubusercontent.com\",\"github-cloud.s3.amazonaws.com\",\"github.com\",\"host.docker.internal\",\"json-schema.org\",\"json.schemastore.org\",\"keyserver.ubuntu.com\",\"lfs.github.com\",\"objects.githubusercontent.com\",\"ocsp.digicert.com\",\"ocsp.geotrust.com\",\"ocsp.globalsign.com\",\"ocsp.identrust.com\",\"ocsp.sectigo.com\",\"ocsp.ssl.com\",\"ocsp.thawte.com\",\"ocsp.usertrust.com\",\"ocsp.verisign.com\",\"packagecloud.io\",\"packages.cloud.google.com\",\"packages.microsoft.com\",\"playwright.download.prss.microsoft.com\",\"ppa.launchpad.net\",\"pypi.org\",\"raw.githubusercontent.com\",\"registry.npmjs.org\",\"s.symcb.com\",\"s.symcd.com\",\"security.ubuntu.com\",\"sentry.io\",\"statsig.anthropic.com\",\"ts-crl.ws.symantec.com\",\"ts-ocsp.ws.symantec.com\"]},\"apiProxy\":{\"enabled\":true,\"enableTokenSteering\":true,\"maxRuns\":500,\"maxAiCredits\":${GH_AW_MAX_AI_CREDITS},\"maxCacheMisses\":5},\"container\":{\"imageTag\":\"0.27.35,squid=sha256:f69282ec7b1326ba53891c399cf5b10475c0d3ccf4e1519b33d234a5427b57d3,agent=sha256:2202f63e8650b2b8b0d38033b44a05387b2b71ad3e690c4d23a34786f5462aed,api-proxy=sha256:755b79d0dfda82bd6b43a208d68666721e504110c5d342a4eeb199802644ff04,cli-proxy=sha256:fe83cd274636efa9de3f456e2b078fae137328b9bb6ee4986ae510acaef0cec5\"},\"logging\":{\"proxyLogsDir\":\"/tmp/gh-aw/sandbox/firewall/logs\",\"auditDir\":\"/tmp/gh-aw/sandbox/firewall/audit\"}}" > "${RUNNER_TEMP}/gh-aw/awf-config.json" + printf '%s\n' "{\"\$schema\":\"https://github.com/github/gh-aw-firewall/releases/download/v0.27.37/awf-config.schema.json\",\"network\":{\"allowDomains\":[\"*.githubusercontent.com\",\"anthropic.com\",\"api.anthropic.com\",\"api.github.com\",\"api.snapcraft.io\",\"archive.ubuntu.com\",\"azure.archive.ubuntu.com\",\"cdn.playwright.dev\",\"codeload.github.com\",\"crl.geotrust.com\",\"crl.globalsign.com\",\"crl.identrust.com\",\"crl.sectigo.com\",\"crl.thawte.com\",\"crl.usertrust.com\",\"crl.verisign.com\",\"crl3.digicert.com\",\"crl4.digicert.com\",\"crls.ssl.com\",\"files.pythonhosted.org\",\"ghcr.io\",\"github-cloud.githubusercontent.com\",\"github-cloud.s3.amazonaws.com\",\"github.com\",\"host.docker.internal\",\"json-schema.org\",\"json.schemastore.org\",\"keyserver.ubuntu.com\",\"lfs.github.com\",\"objects.githubusercontent.com\",\"ocsp.digicert.com\",\"ocsp.geotrust.com\",\"ocsp.globalsign.com\",\"ocsp.identrust.com\",\"ocsp.sectigo.com\",\"ocsp.ssl.com\",\"ocsp.thawte.com\",\"ocsp.usertrust.com\",\"ocsp.verisign.com\",\"packagecloud.io\",\"packages.cloud.google.com\",\"packages.microsoft.com\",\"playwright.download.prss.microsoft.com\",\"ppa.launchpad.net\",\"pypi.org\",\"raw.githubusercontent.com\",\"registry.npmjs.org\",\"s.symcb.com\",\"s.symcd.com\",\"security.ubuntu.com\",\"sentry.io\",\"statsig.anthropic.com\",\"ts-crl.ws.symantec.com\",\"ts-ocsp.ws.symantec.com\"]},\"apiProxy\":{\"enabled\":true,\"enableTokenSteering\":true,\"maxRuns\":500,\"maxAiCredits\":${GH_AW_MAX_AI_CREDITS},\"maxCacheMisses\":5},\"container\":{\"imageTag\":\"0.27.37,squid=sha256:5abc51995e5901c5d1daeefc957301ee409980e2e607391ec22c06cb2513327b,agent=sha256:0d35e8682845f183c1c634699a8e8a6cbe2c271b867031410df74533243c5f67,api-proxy=sha256:fc2970aadaeae05993e76697d29f03dc8bfb9248ff87a8f3d8b0975485a4b317,cli-proxy=sha256:1d5300d9b08e1c4f2ad1830860656a0656383a83280058f17e805a7c3ecda203\"},\"logging\":{\"proxyLogsDir\":\"/tmp/gh-aw/sandbox/firewall/logs\",\"auditDir\":\"/tmp/gh-aw/sandbox/firewall/audit\"}}" > "${RUNNER_TEMP}/gh-aw/awf-config.json" cp "${RUNNER_TEMP}/gh-aw/awf-config.json" /tmp/gh-aw/awf-config.json export GH_AW_MODELS_JSON_PATH="/tmp/gh-aw/models.json" GH_AW_DOCKER_HOST="" @@ -1850,8 +1850,8 @@ jobs: env: GH_AW_SETUP_WORKFLOW_NAME: "Daily VulnHunter Scan" GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/daily-vulnhunter-scan.lock.yml@${{ github.ref }} - GH_AW_INFO_VERSION: "2.1.210" - GH_AW_INFO_AWF_VERSION: "v0.27.35" + GH_AW_INFO_VERSION: "2.1.214" + GH_AW_INFO_AWF_VERSION: "v0.27.37" GH_AW_INFO_ENGINE_ID: "claude" - name: Checkout repository uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 @@ -1956,8 +1956,8 @@ jobs: env: GH_AW_SETUP_WORKFLOW_NAME: "Daily VulnHunter Scan" GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/daily-vulnhunter-scan.lock.yml@${{ github.ref }} - GH_AW_INFO_VERSION: "2.1.210" - GH_AW_INFO_AWF_VERSION: "v0.27.35" + GH_AW_INFO_VERSION: "2.1.214" + GH_AW_INFO_AWF_VERSION: "v0.27.37" GH_AW_INFO_ENGINE_ID: "claude" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" From c465cfc5c6150297c86d80d53abb478bbdcf808c Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 20 Jul 2026 08:02:51 +0000 Subject: [PATCH 3/7] Standardize Copilot assignment permission guidance Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --- actions/setup/js/assign_agent_helpers.cjs | 49 +++++++++---------- .../setup/js/assign_agent_helpers.test.cjs | 10 ++-- actions/setup/js/handle_agent_failure.cjs | 11 +++-- .../setup/js/handle_agent_failure.test.cjs | 38 +++++++++++++- ...ssign_copilot_to_created_issues_failure.md | 22 ++++----- pkg/cli/workflows/test-assign-to-agent.md | 5 +- 6 files changed, 86 insertions(+), 49 deletions(-) diff --git a/actions/setup/js/assign_agent_helpers.cjs b/actions/setup/js/assign_agent_helpers.cjs index d2bdc7bf30c..baf8ed5df9e 100644 --- a/actions/setup/js/assign_agent_helpers.cjs +++ b/actions/setup/js/assign_agent_helpers.cjs @@ -429,23 +429,23 @@ async function assignAgentToIssue( * @param {string} agentName - Agent name for error messages */ function logPermissionError(agentName) { - core.error(`Failed to assign ${agentName}: Insufficient permissions`); + core.error(`Failed to assign ${agentName}: Copilot assignment permission requirements not met`); core.error(""); - core.error("Assigning Copilot coding agent requires the following token permissions:"); + core.error("Copilot assignment needs a Personal Access Token (PAT) that can update issue assignees:"); core.error(" Fine-grained PAT:"); core.error(" - Read access to metadata"); core.error(" - Read and write access to actions, contents, issues, and pull requests"); core.error(" Classic PAT:"); core.error(" - repo scope"); core.error(""); - core.error(" Repository settings:"); - core.error(" - Ensure assignee has access to the repository"); + core.error("Remediation:"); + core.error(" 1. Set GH_AW_AGENT_TOKEN to a PAT with the permissions above"); + core.error(" 2. GitHub App installation tokens are not supported for Copilot assignment"); + core.error(" 3. Ensure the token owner can access the repository and assign users to issues"); + core.error(" 4. Verify Copilot coding agent is enabled and org policy allows bot assignments"); core.error(""); - core.error(" Organization/Enterprise settings and Copilot policy:"); - core.error(" - Check if your org restricts bot assignments"); - core.error(" - Verify Copilot is enabled for your repository"); - core.error(""); - core.info("For more information, see: https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api"); + core.info("gh-aw docs: https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication"); + core.info("GitHub docs: https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api"); } /** @@ -454,28 +454,23 @@ function logPermissionError(agentName) { */ function generatePermissionErrorSummary() { return ` -### ⚠️ Permission Requirements - -Assigning Copilot coding agent requires a token with the correct permissions. See the [official GitHub Copilot cloud agent API documentation](https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api) for details. - -**Fine-grained personal access token** — requires these repository permissions: -- Read access to **metadata** -- Read and write access to **actions**, **contents**, **issues**, and **pull requests** - -**Classic personal access token** — requires the **\`repo\`** scope. +### ⚠️ Copilot Assignment Permission Requirements -**Token capability note:** -- Current token lacks permission for \`POST /repos/{owner}/{repo}/issues/{issue_number}/assignees\`. -- Token must be able to assign users to issues in the target repository. +Copilot assignment failed because the workflow token could not update issue assignees via \`POST /repos/{owner}/{repo}/issues/{issue_number}/assignees\`. -**Recommended remediation paths:** -1. Use a fine-grained PAT with the permissions listed above, or a classic PAT with the \`repo\` scope. -2. Ensure repository settings allow assignee updates. -3. Verify Copilot coding agent is enabled for the repository and organization policy allows bot assignments. +**Required token options** +- **Fine-grained personal access token** — Read access to **metadata** and read/write access to **actions**, **contents**, **issues**, and **pull requests** +- **Classic personal access token** — **\`repo\`** scope -**Why this failed:** The token could not update issue assignees via the REST API. +**Remediation** +- Set \`GH_AW_AGENT_TOKEN\` to a PAT with one of the permission sets above. +- Do not use a GitHub App installation token for Copilot assignment; the API rejects it. +- Ensure the token owner can access the repository and assign users to issues. +- Verify Copilot coding agent is enabled for the repository and organization policy allows bot assignments. -📖 Reference: https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api +**References** +- [gh-aw Copilot Cloud Agent authentication](https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication) +- [Official GitHub Copilot cloud agent API documentation](https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api) `; } diff --git a/actions/setup/js/assign_agent_helpers.test.cjs b/actions/setup/js/assign_agent_helpers.test.cjs index 9fb1d04ea12..559341a94df 100644 --- a/actions/setup/js/assign_agent_helpers.test.cjs +++ b/actions/setup/js/assign_agent_helpers.test.cjs @@ -437,7 +437,9 @@ describe("assign_agent_helpers.cjs", () => { const result = await assignAgentToIssue("id", "agent", [], "copilot", null, null, null, null, null, restClient, taskContext); expect(result).toBe(false); - expect(mockCore.error).toHaveBeenCalledWith(expect.stringContaining("Insufficient permissions")); + expect(mockCore.error).toHaveBeenCalledWith(expect.stringContaining("Copilot assignment permission requirements not met")); + expect(mockCore.error).toHaveBeenCalledWith(expect.stringContaining("GH_AW_AGENT_TOKEN")); + expect(mockCore.info).toHaveBeenCalledWith(expect.stringContaining("github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication")); }); }); @@ -445,10 +447,12 @@ describe("assign_agent_helpers.cjs", () => { it("should return markdown content with permission requirements", () => { const summary = generatePermissionErrorSummary(); - expect(summary).toContain("### ⚠️ Permission Requirements"); - expect(summary).toContain("Fine-grained personal access token"); + expect(summary).toContain("### ⚠️ Copilot Assignment Permission Requirements"); + expect(summary).toContain("GH_AW_AGENT_TOKEN"); + expect(summary).toContain("GitHub App installation token"); expect(summary).toContain("actions**, **contents**, **issues**"); expect(summary).toContain("POST /repos/{owner}/{repo}/issues/{issue_number}/assignees"); + expect(summary).toContain("https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication"); expect(summary).toContain("https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api"); }); }); diff --git a/actions/setup/js/handle_agent_failure.cjs b/actions/setup/js/handle_agent_failure.cjs index a66e58d29fb..438e36e70b2 100644 --- a/actions/setup/js/handle_agent_failure.cjs +++ b/actions/setup/js/handle_agent_failure.cjs @@ -2199,10 +2199,13 @@ function buildAssignmentErrorsContext(assignmentErrors) { } } - context += "\nTo resolve this, verify the agent token and Copilot access configuration:\n"; - context += "- Configure a valid `GH_AW_AGENT_TOKEN` as a fine-grained PAT with **Agent tasks: read and write** permission (GitHub App installation tokens are not supported)\n"; - context += "- Ensure Copilot coding agent is enabled for this repository and a Copilot Business or Enterprise subscription is active\n"; - context += "- Docs: https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication\n\n"; + context += "\nTo resolve this, verify the token and Copilot assignment configuration:\n"; + context += "- Set `GH_AW_AGENT_TOKEN` to a fine-grained PAT with **metadata: read** and **actions**, **contents**, **issues**, and **pull requests: write**, or use a classic PAT with `repo`\n"; + context += "- Do not use a GitHub App installation token for Copilot assignment; the API rejects it\n"; + context += "- Ensure the token owner can access the repository and assign users to issues\n"; + context += "- Verify Copilot coding agent is enabled for this repository and organization policy allows bot assignments\n"; + context += "- Docs: https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication\n"; + context += "- API reference: https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api\n\n"; return context; } diff --git a/actions/setup/js/handle_agent_failure.test.cjs b/actions/setup/js/handle_agent_failure.test.cjs index f3cc1961ece..56e7b51e987 100644 --- a/actions/setup/js/handle_agent_failure.test.cjs +++ b/actions/setup/js/handle_agent_failure.test.cjs @@ -4,6 +4,11 @@ import { describe, it, expect, beforeEach, afterEach, vi } from "vitest"; import { createRequire } from "module"; const require = createRequire(import.meta.url); +const TEST_PROMPTS_DIR = new URL("../md/", import.meta.url).pathname; + +if (!process.env.GH_AW_PROMPTS_DIR) { + process.env.GH_AW_PROMPTS_DIR = TEST_PROMPTS_DIR; +} describe("handle_agent_failure", () => { let main; @@ -13,11 +18,15 @@ describe("handle_agent_failure", () => { let buildFailureIssueTitle; let buildSecretVerificationContext; let buildAssignmentErrorsContext; + let buildAssignCopilotFailureContext; let getActionFailureIssueExpiresHours; const ENGINE_RATE_LIMIT_TEMPLATE = "> [!WARNING]\n> **Engine Rate Limited (HTTP 429)**\n> OTLP telemetry\n> {engine_label}\n"; const ENGINE_MAX_RUNS_EXCEEDED_TEMPLATE = "> [!WARNING]\n> **Engine Max Runs Exceeded**\n> max-runs guardrail\n> {engine_label}\n"; + let originalPromptsDir; beforeEach(() => { + originalPromptsDir = process.env.GH_AW_PROMPTS_DIR; + process.env.GH_AW_PROMPTS_DIR = TEST_PROMPTS_DIR; // Provide minimal GitHub Actions globals expected by require-time code global.core = { info: vi.fn(), @@ -40,6 +49,7 @@ describe("handle_agent_failure", () => { buildFailureIssueTitle, buildSecretVerificationContext, buildAssignmentErrorsContext, + buildAssignCopilotFailureContext, getActionFailureIssueExpiresHours, } = require("./handle_agent_failure.cjs")); }); @@ -51,6 +61,11 @@ describe("handle_agent_failure", () => { delete process.env.GITHUB_SHA; delete process.env.GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURS; delete process.env.GH_AW_GROUP_REPORTS; + if (originalPromptsDir === undefined) { + delete process.env.GH_AW_PROMPTS_DIR; + } else { + process.env.GH_AW_PROMPTS_DIR = originalPromptsDir; + } }); describe("getActionFailureIssueExpiresHours", () => { @@ -1378,9 +1393,30 @@ describe("handle_agent_failure", () => { expect(result).toContain("Issue #42 (agent: copilot): Bad credentials"); expect(result).toContain("PR #7 (agent: copilot): copilot coding agent is not available for this repository"); expect(result).toContain("GH_AW_AGENT_TOKEN"); - expect(result).toContain("Agent tasks: read and write"); + expect(result).toContain("metadata: read"); + expect(result).toContain("GitHub App installation token"); + expect(result).toContain("https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication"); + expect(result).toContain("https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api"); expect(result).not.toContain("copilot-requests: write"); + }); + }); + + describe("buildAssignCopilotFailureContext", () => { + it("returns empty string when there are no copilot assignment failures", () => { + expect(buildAssignCopilotFailureContext(false, "")).toBe(""); + }); + + it("renders standardized copilot assignment remediation guidance", () => { + const result = buildAssignCopilotFailureContext(true, "issue:42:copilot:Bad credentials"); + + expect(result).toContain("Copilot Assignment Failed"); + expect(result).toContain("Issue #42: Bad credentials"); + expect(result).toContain("GH_AW_AGENT_TOKEN"); + expect(result).toContain("metadata"); + expect(result).toContain("GitHub App installation token"); + expect(result).toContain("YOUR_AGENT_PAT"); expect(result).toContain("https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication"); + expect(result).toContain("https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api"); }); }); diff --git a/actions/setup/md/assign_copilot_to_created_issues_failure.md b/actions/setup/md/assign_copilot_to_created_issues_failure.md index 7d245e7e4f9..a1dae867f91 100644 --- a/actions/setup/md/assign_copilot_to_created_issues_failure.md +++ b/actions/setup/md/assign_copilot_to_created_issues_failure.md @@ -1,21 +1,19 @@ -**Copilot Assignment Failed**: The workflow created an issue but could not assign the Copilot coding agent to it. This typically happens when: - -- The `GH_AW_AGENT_TOKEN` secret is missing or has expired -- The token does not have the `issues: write` permission -- The Copilot coding agent is not available for this repository -- GitHub API credentials are invalid (`Bad credentials`) +**Copilot Assignment Failed**: The workflow created an issue but could not assign the Copilot coding agent because the workflow token could not update issue assignees. **Failed assignments:** {issues} -To resolve this, verify that: -1. The `GH_AW_AGENT_TOKEN` secret is configured in your repository settings -2. The token belongs to an account with an active Copilot subscription -3. The token has `issues: write` permission for this repository +To resolve this: +1. Set `GH_AW_AGENT_TOKEN` to a fine-grained PAT with read access to `metadata` and read/write access to `actions`, `contents`, `issues`, and `pull requests`, or use a classic PAT with the `repo` scope. +2. Do not use a GitHub App installation token for Copilot assignment; the API rejects it. +3. Ensure the token owner can access the repository and assign users to issues. +4. Verify Copilot coding agent is enabled for this repository and organization policy allows bot assignments. ```bash -gh aw secrets set GH_AW_AGENT_TOKEN --value "YOUR_TOKEN" +gh aw secrets set GH_AW_AGENT_TOKEN --value "YOUR_AGENT_PAT" ``` -See: https://github.com/github/gh-aw/blob/main/docs/src/content/docs/reference/auth.mdx +See: +- https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication +- https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api diff --git a/pkg/cli/workflows/test-assign-to-agent.md b/pkg/cli/workflows/test-assign-to-agent.md index cae86dd8fa1..c3271343c06 100644 --- a/pkg/cli/workflows/test-assign-to-agent.md +++ b/pkg/cli/workflows/test-assign-to-agent.md @@ -18,11 +18,12 @@ permissions: pull-requests: read # NOTE: Assigning Copilot coding agent requires: -# 1. A Personal Access Token (PAT) or GitHub App token with repo scope +# 1. A Personal Access Token (PAT) # - The standard GITHUB_TOKEN does NOT have permission to assign bot agents +# - GitHub App installation tokens are NOT supported for Copilot assignment # - Create a PAT at: https://github.com/settings/tokens # - Add it as a repository secret named GH_AW_AGENT_TOKEN -# - Required scopes: repo (full control) or fine-grained: actions, contents, issues, pull-requests (write) +# - Required scopes: repo (classic PAT) or fine-grained: metadata (read) plus actions, contents, issues, pull-requests (write) # # 2. All four workflow permissions declared above (for the safe output job) # From 5b4c1075c5bb28e609485b966059a532b6045a41 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 20 Jul 2026 08:13:16 +0000 Subject: [PATCH 4/7] Finalize assignment guidance test coverage Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --- actions/setup/js/handle_agent_failure.test.cjs | 13 ------------- 1 file changed, 13 deletions(-) diff --git a/actions/setup/js/handle_agent_failure.test.cjs b/actions/setup/js/handle_agent_failure.test.cjs index 56e7b51e987..5b1ed74aa31 100644 --- a/actions/setup/js/handle_agent_failure.test.cjs +++ b/actions/setup/js/handle_agent_failure.test.cjs @@ -4,11 +4,6 @@ import { describe, it, expect, beforeEach, afterEach, vi } from "vitest"; import { createRequire } from "module"; const require = createRequire(import.meta.url); -const TEST_PROMPTS_DIR = new URL("../md/", import.meta.url).pathname; - -if (!process.env.GH_AW_PROMPTS_DIR) { - process.env.GH_AW_PROMPTS_DIR = TEST_PROMPTS_DIR; -} describe("handle_agent_failure", () => { let main; @@ -22,11 +17,8 @@ describe("handle_agent_failure", () => { let getActionFailureIssueExpiresHours; const ENGINE_RATE_LIMIT_TEMPLATE = "> [!WARNING]\n> **Engine Rate Limited (HTTP 429)**\n> OTLP telemetry\n> {engine_label}\n"; const ENGINE_MAX_RUNS_EXCEEDED_TEMPLATE = "> [!WARNING]\n> **Engine Max Runs Exceeded**\n> max-runs guardrail\n> {engine_label}\n"; - let originalPromptsDir; beforeEach(() => { - originalPromptsDir = process.env.GH_AW_PROMPTS_DIR; - process.env.GH_AW_PROMPTS_DIR = TEST_PROMPTS_DIR; // Provide minimal GitHub Actions globals expected by require-time code global.core = { info: vi.fn(), @@ -61,11 +53,6 @@ describe("handle_agent_failure", () => { delete process.env.GITHUB_SHA; delete process.env.GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURS; delete process.env.GH_AW_GROUP_REPORTS; - if (originalPromptsDir === undefined) { - delete process.env.GH_AW_PROMPTS_DIR; - } else { - process.env.GH_AW_PROMPTS_DIR = originalPromptsDir; - } }); describe("getActionFailureIssueExpiresHours", () => { From 8cd47700ae98151cfcdb9884aa47b4d4346ea478 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 20 Jul 2026 08:38:37 +0000 Subject: [PATCH 5/7] Refactor Copilot assignment guidance templates Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --- actions/setup/js/assign_agent_helpers.cjs | 48 +++++-------------- .../setup/js/assign_agent_helpers.test.cjs | 7 +++ actions/setup/js/handle_agent_failure.cjs | 20 +++----- .../setup/js/handle_agent_failure.test.cjs | 8 ++++ .../md/copilot_assignment_errors_context.md | 11 +++++ .../md/copilot_assignment_permission_error.md | 17 +++++++ ...ilot_assignment_permission_requirements.md | 17 +++++++ 7 files changed, 79 insertions(+), 49 deletions(-) create mode 100644 actions/setup/md/copilot_assignment_errors_context.md create mode 100644 actions/setup/md/copilot_assignment_permission_error.md create mode 100644 actions/setup/md/copilot_assignment_permission_requirements.md diff --git a/actions/setup/js/assign_agent_helpers.cjs b/actions/setup/js/assign_agent_helpers.cjs index baf8ed5df9e..d7fb70600e2 100644 --- a/actions/setup/js/assign_agent_helpers.cjs +++ b/actions/setup/js/assign_agent_helpers.cjs @@ -3,6 +3,7 @@ // @safe-outputs-exempt SEC-004 — body fields are read-only API context, never written back const { getErrorMessage } = require("./error_helpers.cjs"); +const { getPromptPath, renderTemplateFromFile } = require("./messages_core.cjs"); /** * Shared helper functions for assigning coding agents (like Copilot) to issues. @@ -429,23 +430,15 @@ async function assignAgentToIssue( * @param {string} agentName - Agent name for error messages */ function logPermissionError(agentName) { - core.error(`Failed to assign ${agentName}: Copilot assignment permission requirements not met`); - core.error(""); - core.error("Copilot assignment needs a Personal Access Token (PAT) that can update issue assignees:"); - core.error(" Fine-grained PAT:"); - core.error(" - Read access to metadata"); - core.error(" - Read and write access to actions, contents, issues, and pull requests"); - core.error(" Classic PAT:"); - core.error(" - repo scope"); - core.error(""); - core.error("Remediation:"); - core.error(" 1. Set GH_AW_AGENT_TOKEN to a PAT with the permissions above"); - core.error(" 2. GitHub App installation tokens are not supported for Copilot assignment"); - core.error(" 3. Ensure the token owner can access the repository and assign users to issues"); - core.error(" 4. Verify Copilot coding agent is enabled and org policy allows bot assignments"); - core.error(""); - core.info("gh-aw docs: https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication"); - core.info("GitHub docs: https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api"); + const templatePath = getPromptPath("copilot_assignment_permission_error.md"); + const rendered = renderTemplateFromFile(templatePath, { agent_name: agentName }); + for (const line of rendered.split("\n")) { + if (line.startsWith("gh-aw docs:") || line.startsWith("GitHub docs:")) { + core.info(line); + } else { + core.error(line); + } + } } /** @@ -453,25 +446,8 @@ function logPermissionError(agentName) { * @returns {string} Markdown content for permission error guidance */ function generatePermissionErrorSummary() { - return ` -### ⚠️ Copilot Assignment Permission Requirements - -Copilot assignment failed because the workflow token could not update issue assignees via \`POST /repos/{owner}/{repo}/issues/{issue_number}/assignees\`. - -**Required token options** -- **Fine-grained personal access token** — Read access to **metadata** and read/write access to **actions**, **contents**, **issues**, and **pull requests** -- **Classic personal access token** — **\`repo\`** scope - -**Remediation** -- Set \`GH_AW_AGENT_TOKEN\` to a PAT with one of the permission sets above. -- Do not use a GitHub App installation token for Copilot assignment; the API rejects it. -- Ensure the token owner can access the repository and assign users to issues. -- Verify Copilot coding agent is enabled for the repository and organization policy allows bot assignments. - -**References** -- [gh-aw Copilot Cloud Agent authentication](https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication) -- [Official GitHub Copilot cloud agent API documentation](https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api) -`; + const templatePath = getPromptPath("copilot_assignment_permission_requirements.md"); + return renderTemplateFromFile(templatePath, {}); } /** diff --git a/actions/setup/js/assign_agent_helpers.test.cjs b/actions/setup/js/assign_agent_helpers.test.cjs index 559341a94df..64bfbc86d7b 100644 --- a/actions/setup/js/assign_agent_helpers.test.cjs +++ b/actions/setup/js/assign_agent_helpers.test.cjs @@ -1,4 +1,11 @@ import { describe, it, expect, beforeEach, vi } from "vitest"; +import { cpSync, mkdirSync } from "fs"; +import path from "path"; + +const promptsDir = new URL("../md", import.meta.url).pathname; +const runtimePromptsDir = path.join(process.env.RUNNER_TEMP || "/tmp", "gh-aw", "prompts"); +mkdirSync(runtimePromptsDir, { recursive: true }); +cpSync(promptsDir, runtimePromptsDir, { recursive: true }); // Mock the global objects that GitHub Actions provides const mockCore = { diff --git a/actions/setup/js/handle_agent_failure.cjs b/actions/setup/js/handle_agent_failure.cjs index 438e36e70b2..d958e4585e6 100644 --- a/actions/setup/js/handle_agent_failure.cjs +++ b/actions/setup/js/handle_agent_failure.cjs @@ -2184,10 +2184,8 @@ function buildAssignmentErrorsContext(assignmentErrors) { return ""; } - let context = buildWarningAlertLine("Agent Assignment Failed", "Failed to assign agent to issues or pull requests."); - context += "\n**Assignment Errors:**\n"; - const errorLines = assignmentErrors.split("\n").filter(line => line.trim()); + let renderedErrors = ""; for (const errorLine of errorLines) { const parts = errorLine.split(":"); if (parts.length >= 4) { @@ -2195,19 +2193,15 @@ function buildAssignmentErrorsContext(assignmentErrors) { const number = parts[1]; const agent = parts[2]; const error = parts.slice(3).join(":"); - context += `- ${type === "issue" ? "Issue" : "PR"} #${number} (agent: ${agent}): ${error}\n`; + renderedErrors += `- ${type === "issue" ? "Issue" : "PR"} #${number} (agent: ${agent}): ${error}\n`; } } - context += "\nTo resolve this, verify the token and Copilot assignment configuration:\n"; - context += "- Set `GH_AW_AGENT_TOKEN` to a fine-grained PAT with **metadata: read** and **actions**, **contents**, **issues**, and **pull requests: write**, or use a classic PAT with `repo`\n"; - context += "- Do not use a GitHub App installation token for Copilot assignment; the API rejects it\n"; - context += "- Ensure the token owner can access the repository and assign users to issues\n"; - context += "- Verify Copilot coding agent is enabled for this repository and organization policy allows bot assignments\n"; - context += "- Docs: https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication\n"; - context += "- API reference: https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api\n\n"; - - return context; + const templatePath = getPromptPath("copilot_assignment_errors_context.md"); + return renderTemplateFromFile(templatePath, { + warning_line: buildWarningAlertLine("Agent Assignment Failed", "Failed to assign agent to issues or pull requests."), + assignment_errors: renderedErrors, + }); } /** * Build a context string when assigning the Copilot coding agent to created issues failed. diff --git a/actions/setup/js/handle_agent_failure.test.cjs b/actions/setup/js/handle_agent_failure.test.cjs index 5b1ed74aa31..77e7f20c738 100644 --- a/actions/setup/js/handle_agent_failure.test.cjs +++ b/actions/setup/js/handle_agent_failure.test.cjs @@ -2,8 +2,14 @@ import { describe, it, expect, beforeEach, afterEach, vi } from "vitest"; import { createRequire } from "module"; +import { cpSync, mkdirSync } from "fs"; +import path from "path"; const require = createRequire(import.meta.url); +const promptsDir = new URL("../md", import.meta.url).pathname; +const runtimePromptsDir = path.join(process.env.RUNNER_TEMP || "/tmp", "gh-aw", "prompts"); +mkdirSync(runtimePromptsDir, { recursive: true }); +cpSync(promptsDir, runtimePromptsDir, { recursive: true }); describe("handle_agent_failure", () => { let main; @@ -1374,6 +1380,7 @@ describe("handle_agent_failure", () => { }); it("renders assignment failures with token guidance docs", () => { + process.env.GH_AW_PROMPTS_DIR = runtimePromptsDir; const result = buildAssignmentErrorsContext("issue:42:copilot:Bad credentials\npr:7:copilot:copilot coding agent is not available for this repository"); expect(result).toContain("Agent Assignment Failed"); @@ -1394,6 +1401,7 @@ describe("handle_agent_failure", () => { }); it("renders standardized copilot assignment remediation guidance", () => { + process.env.GH_AW_PROMPTS_DIR = runtimePromptsDir; const result = buildAssignCopilotFailureContext(true, "issue:42:copilot:Bad credentials"); expect(result).toContain("Copilot Assignment Failed"); diff --git a/actions/setup/md/copilot_assignment_errors_context.md b/actions/setup/md/copilot_assignment_errors_context.md new file mode 100644 index 00000000000..bdc94087822 --- /dev/null +++ b/actions/setup/md/copilot_assignment_errors_context.md @@ -0,0 +1,11 @@ +{warning_line} +**Assignment Errors:** +{assignment_errors} + +To resolve this, verify the token and Copilot assignment configuration: +- Set `GH_AW_AGENT_TOKEN` to a fine-grained PAT with **metadata: read** and **actions**, **contents**, **issues**, and **pull requests: write**, or use a classic PAT with `repo` +- Do not use a GitHub App installation token for Copilot assignment; the API rejects it +- Ensure the token owner can access the repository and assign users to issues +- Verify Copilot coding agent is enabled for this repository and organization policy allows bot assignments +- Docs: https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication +- API reference: https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api diff --git a/actions/setup/md/copilot_assignment_permission_error.md b/actions/setup/md/copilot_assignment_permission_error.md new file mode 100644 index 00000000000..5649944f4f0 --- /dev/null +++ b/actions/setup/md/copilot_assignment_permission_error.md @@ -0,0 +1,17 @@ +Failed to assign {agent_name}: Copilot assignment permission requirements not met + +Copilot assignment needs a Personal Access Token (PAT) that can update issue assignees: + Fine-grained PAT: + - Read access to metadata + - Read and write access to actions, contents, issues, and pull requests + Classic PAT: + - repo scope + +Remediation: + 1. Set GH_AW_AGENT_TOKEN to a PAT with the permissions above + 2. GitHub App installation tokens are not supported for Copilot assignment + 3. Ensure the token owner can access the repository and assign users to issues + 4. Verify Copilot coding agent is enabled and org policy allows bot assignments + +gh-aw docs: https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication +GitHub docs: https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api diff --git a/actions/setup/md/copilot_assignment_permission_requirements.md b/actions/setup/md/copilot_assignment_permission_requirements.md new file mode 100644 index 00000000000..8634dcf5536 --- /dev/null +++ b/actions/setup/md/copilot_assignment_permission_requirements.md @@ -0,0 +1,17 @@ +### ⚠️ Copilot Assignment Permission Requirements + +Copilot assignment failed because the workflow token could not update issue assignees via `POST /repos/{owner}/{repo}/issues/{issue_number}/assignees`. + +**Required token options** +- **Fine-grained personal access token** — Read access to **metadata** and read/write access to **actions**, **contents**, **issues**, and **pull requests** +- **Classic personal access token** — **`repo`** scope + +**Remediation** +- Set `GH_AW_AGENT_TOKEN` to a PAT with one of the permission sets above. +- Do not use a GitHub App installation token for Copilot assignment; the API rejects it. +- Ensure the token owner can access the repository and assign users to issues. +- Verify Copilot coding agent is enabled for the repository and organization policy allows bot assignments. + +**References** +- [gh-aw Copilot Cloud Agent authentication](https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication) +- [Official GitHub Copilot cloud agent API documentation](https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api) From 54e6026a18a30713aeeff8d7b68c1720c7f515d3 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 20 Jul 2026 08:47:33 +0000 Subject: [PATCH 6/7] Refine assignment template rendering Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --- actions/setup/js/assign_agent_helpers.cjs | 18 ++++++++++-------- actions/setup/js/assign_agent_helpers.test.cjs | 8 ++------ actions/setup/js/handle_agent_failure.cjs | 2 +- actions/setup/js/handle_agent_failure.test.cjs | 8 ++------ actions/setup/js/test_prompt_templates.js | 10 ++++++++++ .../md/copilot_assignment_permission_error.md | 3 --- ...copilot_assignment_permission_references.md | 2 ++ 7 files changed, 27 insertions(+), 24 deletions(-) create mode 100644 actions/setup/js/test_prompt_templates.js create mode 100644 actions/setup/md/copilot_assignment_permission_references.md diff --git a/actions/setup/js/assign_agent_helpers.cjs b/actions/setup/js/assign_agent_helpers.cjs index d7fb70600e2..076caba3acd 100644 --- a/actions/setup/js/assign_agent_helpers.cjs +++ b/actions/setup/js/assign_agent_helpers.cjs @@ -430,14 +430,16 @@ async function assignAgentToIssue( * @param {string} agentName - Agent name for error messages */ function logPermissionError(agentName) { - const templatePath = getPromptPath("copilot_assignment_permission_error.md"); - const rendered = renderTemplateFromFile(templatePath, { agent_name: agentName }); - for (const line of rendered.split("\n")) { - if (line.startsWith("gh-aw docs:") || line.startsWith("GitHub docs:")) { - core.info(line); - } else { - core.error(line); - } + const errorTemplatePath = getPromptPath("copilot_assignment_permission_error.md"); + const referencesTemplatePath = getPromptPath("copilot_assignment_permission_references.md"); + const renderedError = renderTemplateFromFile(errorTemplatePath, { agent_name: agentName }).trimEnd(); + const renderedReferences = renderTemplateFromFile(referencesTemplatePath, {}).trimEnd(); + + for (const line of renderedError.split("\n")) { + core.error(line); + } + for (const line of renderedReferences.split("\n")) { + core.info(line); } } diff --git a/actions/setup/js/assign_agent_helpers.test.cjs b/actions/setup/js/assign_agent_helpers.test.cjs index 64bfbc86d7b..61bdc62a179 100644 --- a/actions/setup/js/assign_agent_helpers.test.cjs +++ b/actions/setup/js/assign_agent_helpers.test.cjs @@ -1,11 +1,7 @@ import { describe, it, expect, beforeEach, vi } from "vitest"; -import { cpSync, mkdirSync } from "fs"; -import path from "path"; +import { syncRuntimePromptTemplates } from "./test_prompt_templates.js"; -const promptsDir = new URL("../md", import.meta.url).pathname; -const runtimePromptsDir = path.join(process.env.RUNNER_TEMP || "/tmp", "gh-aw", "prompts"); -mkdirSync(runtimePromptsDir, { recursive: true }); -cpSync(promptsDir, runtimePromptsDir, { recursive: true }); +syncRuntimePromptTemplates(import.meta.url); // Mock the global objects that GitHub Actions provides const mockCore = { diff --git a/actions/setup/js/handle_agent_failure.cjs b/actions/setup/js/handle_agent_failure.cjs index d958e4585e6..c190b7b18fb 100644 --- a/actions/setup/js/handle_agent_failure.cjs +++ b/actions/setup/js/handle_agent_failure.cjs @@ -2200,7 +2200,7 @@ function buildAssignmentErrorsContext(assignmentErrors) { const templatePath = getPromptPath("copilot_assignment_errors_context.md"); return renderTemplateFromFile(templatePath, { warning_line: buildWarningAlertLine("Agent Assignment Failed", "Failed to assign agent to issues or pull requests."), - assignment_errors: renderedErrors, + assignment_errors: renderedErrors.trimEnd(), }); } /** diff --git a/actions/setup/js/handle_agent_failure.test.cjs b/actions/setup/js/handle_agent_failure.test.cjs index 77e7f20c738..4a2f9fa341e 100644 --- a/actions/setup/js/handle_agent_failure.test.cjs +++ b/actions/setup/js/handle_agent_failure.test.cjs @@ -2,14 +2,10 @@ import { describe, it, expect, beforeEach, afterEach, vi } from "vitest"; import { createRequire } from "module"; -import { cpSync, mkdirSync } from "fs"; -import path from "path"; +import { syncRuntimePromptTemplates } from "./test_prompt_templates.js"; const require = createRequire(import.meta.url); -const promptsDir = new URL("../md", import.meta.url).pathname; -const runtimePromptsDir = path.join(process.env.RUNNER_TEMP || "/tmp", "gh-aw", "prompts"); -mkdirSync(runtimePromptsDir, { recursive: true }); -cpSync(promptsDir, runtimePromptsDir, { recursive: true }); +const { runtimePromptsDir } = syncRuntimePromptTemplates(import.meta.url); describe("handle_agent_failure", () => { let main; diff --git a/actions/setup/js/test_prompt_templates.js b/actions/setup/js/test_prompt_templates.js new file mode 100644 index 00000000000..3b6d79eff69 --- /dev/null +++ b/actions/setup/js/test_prompt_templates.js @@ -0,0 +1,10 @@ +import { cpSync, mkdirSync } from "fs"; +import path from "path"; + +export function syncRuntimePromptTemplates(metaUrl) { + const promptsDir = new URL("../md", metaUrl).pathname; + const runtimePromptsDir = path.join(process.env.RUNNER_TEMP || "/tmp", "gh-aw", "prompts"); + mkdirSync(runtimePromptsDir, { recursive: true }); + cpSync(promptsDir, runtimePromptsDir, { recursive: true }); + return { promptsDir, runtimePromptsDir }; +} diff --git a/actions/setup/md/copilot_assignment_permission_error.md b/actions/setup/md/copilot_assignment_permission_error.md index 5649944f4f0..4cdb2b98582 100644 --- a/actions/setup/md/copilot_assignment_permission_error.md +++ b/actions/setup/md/copilot_assignment_permission_error.md @@ -12,6 +12,3 @@ Remediation: 2. GitHub App installation tokens are not supported for Copilot assignment 3. Ensure the token owner can access the repository and assign users to issues 4. Verify Copilot coding agent is enabled and org policy allows bot assignments - -gh-aw docs: https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication -GitHub docs: https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api diff --git a/actions/setup/md/copilot_assignment_permission_references.md b/actions/setup/md/copilot_assignment_permission_references.md new file mode 100644 index 00000000000..b6323d456bc --- /dev/null +++ b/actions/setup/md/copilot_assignment_permission_references.md @@ -0,0 +1,2 @@ +gh-aw docs: https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication +GitHub docs: https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api From fcc498e972c59fd4ade2fdfda646b928f949acac Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 20 Jul 2026 09:53:48 +0000 Subject: [PATCH 7/7] Fix prompt template test isolation Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --- .../setup/js/assign_agent_helpers.test.cjs | 18 +++++- .../setup/js/handle_agent_failure.test.cjs | 64 ++++++++++++------- .../docs/reference/copilot-cloud-agent.mdx | 2 +- 3 files changed, 58 insertions(+), 26 deletions(-) diff --git a/actions/setup/js/assign_agent_helpers.test.cjs b/actions/setup/js/assign_agent_helpers.test.cjs index 61bdc62a179..f5f70a2e256 100644 --- a/actions/setup/js/assign_agent_helpers.test.cjs +++ b/actions/setup/js/assign_agent_helpers.test.cjs @@ -1,7 +1,7 @@ -import { describe, it, expect, beforeEach, vi } from "vitest"; +import { describe, it, expect, beforeEach, beforeAll, afterAll, vi } from "vitest"; import { syncRuntimePromptTemplates } from "./test_prompt_templates.js"; -syncRuntimePromptTemplates(import.meta.url); +const { runtimePromptsDir } = syncRuntimePromptTemplates(import.meta.url); // Mock the global objects that GitHub Actions provides const mockCore = { @@ -37,6 +37,20 @@ const { AGENT_LOGIN_NAMES, getAgentName, getAgentLogins, getAvailableAgentLogins await import("./assign_agent_helpers.cjs"); describe("assign_agent_helpers.cjs", () => { + const originalPromptsDir = process.env.GH_AW_PROMPTS_DIR; + + beforeAll(() => { + process.env.GH_AW_PROMPTS_DIR = runtimePromptsDir; + }); + + afterAll(() => { + if (originalPromptsDir === undefined) { + delete process.env.GH_AW_PROMPTS_DIR; + return; + } + process.env.GH_AW_PROMPTS_DIR = originalPromptsDir; + }); + beforeEach(() => { vi.clearAllMocks(); }); diff --git a/actions/setup/js/handle_agent_failure.test.cjs b/actions/setup/js/handle_agent_failure.test.cjs index 4a2f9fa341e..813483cc87a 100644 --- a/actions/setup/js/handle_agent_failure.test.cjs +++ b/actions/setup/js/handle_agent_failure.test.cjs @@ -1376,18 +1376,27 @@ describe("handle_agent_failure", () => { }); it("renders assignment failures with token guidance docs", () => { - process.env.GH_AW_PROMPTS_DIR = runtimePromptsDir; - const result = buildAssignmentErrorsContext("issue:42:copilot:Bad credentials\npr:7:copilot:copilot coding agent is not available for this repository"); - - expect(result).toContain("Agent Assignment Failed"); - expect(result).toContain("Issue #42 (agent: copilot): Bad credentials"); - expect(result).toContain("PR #7 (agent: copilot): copilot coding agent is not available for this repository"); - expect(result).toContain("GH_AW_AGENT_TOKEN"); - expect(result).toContain("metadata: read"); - expect(result).toContain("GitHub App installation token"); - expect(result).toContain("https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication"); - expect(result).toContain("https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api"); - expect(result).not.toContain("copilot-requests: write"); + const originalPromptsDir = process.env.GH_AW_PROMPTS_DIR; + try { + process.env.GH_AW_PROMPTS_DIR = runtimePromptsDir; + const result = buildAssignmentErrorsContext("issue:42:copilot:Bad credentials\npr:7:copilot:copilot coding agent is not available for this repository"); + + expect(result).toContain("Agent Assignment Failed"); + expect(result).toContain("Issue #42 (agent: copilot): Bad credentials"); + expect(result).toContain("PR #7 (agent: copilot): copilot coding agent is not available for this repository"); + expect(result).toContain("GH_AW_AGENT_TOKEN"); + expect(result).toContain("metadata: read"); + expect(result).toContain("GitHub App installation token"); + expect(result).toContain("https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication"); + expect(result).toContain("https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api"); + expect(result).not.toContain("copilot-requests: write"); + } finally { + if (originalPromptsDir === undefined) { + delete process.env.GH_AW_PROMPTS_DIR; + } else { + process.env.GH_AW_PROMPTS_DIR = originalPromptsDir; + } + } }); }); @@ -1397,17 +1406,26 @@ describe("handle_agent_failure", () => { }); it("renders standardized copilot assignment remediation guidance", () => { - process.env.GH_AW_PROMPTS_DIR = runtimePromptsDir; - const result = buildAssignCopilotFailureContext(true, "issue:42:copilot:Bad credentials"); - - expect(result).toContain("Copilot Assignment Failed"); - expect(result).toContain("Issue #42: Bad credentials"); - expect(result).toContain("GH_AW_AGENT_TOKEN"); - expect(result).toContain("metadata"); - expect(result).toContain("GitHub App installation token"); - expect(result).toContain("YOUR_AGENT_PAT"); - expect(result).toContain("https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication"); - expect(result).toContain("https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api"); + const originalPromptsDir = process.env.GH_AW_PROMPTS_DIR; + try { + process.env.GH_AW_PROMPTS_DIR = runtimePromptsDir; + const result = buildAssignCopilotFailureContext(true, "issue:42:copilot:Bad credentials"); + + expect(result).toContain("Copilot Assignment Failed"); + expect(result).toContain("Issue #42: Bad credentials"); + expect(result).toContain("GH_AW_AGENT_TOKEN"); + expect(result).toContain("metadata"); + expect(result).toContain("GitHub App installation token"); + expect(result).toContain("YOUR_AGENT_PAT"); + expect(result).toContain("https://github.github.com/gh-aw/reference/copilot-cloud-agent/#authentication"); + expect(result).toContain("https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api"); + } finally { + if (originalPromptsDir === undefined) { + delete process.env.GH_AW_PROMPTS_DIR; + } else { + process.env.GH_AW_PROMPTS_DIR = originalPromptsDir; + } + } }); }); diff --git a/docs/src/content/docs/reference/copilot-cloud-agent.mdx b/docs/src/content/docs/reference/copilot-cloud-agent.mdx index 5a835ee3a5e..c7959ef9092 100644 --- a/docs/src/content/docs/reference/copilot-cloud-agent.mdx +++ b/docs/src/content/docs/reference/copilot-cloud-agent.mdx @@ -115,7 +115,7 @@ The required token type and permissions depend on whether you own the repository ### Using a GitHub App :::caution[GitHub App tokens are not supported for Copilot assignment] -The Copilot assignment API only accepts fine-grained PATs — GitHub App installation tokens are rejected regardless of permissions. When `github-app:` is configured in `safe-outputs`, `assign-to-agent` falls back to: explicit `github-token:` in `assign-to-agent`, then `github-token:` at the `safe-outputs` level, then the magic secret chain (`GH_AW_AGENT_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN`). +The Copilot assignment API requires a Personal Access Token (fine-grained PAT with the permissions above, or a classic PAT with `repo`) — GitHub App installation tokens are rejected regardless of permissions. When `github-app:` is configured in `safe-outputs`, `assign-to-agent` falls back to: explicit `github-token:` in `assign-to-agent`, then `github-token:` at the `safe-outputs` level, then the magic secret chain (`GH_AW_AGENT_TOKEN || GH_AW_GITHUB_TOKEN || GITHUB_TOKEN`). ::: ### Using a magic secret