diff --git a/.github/aw/actions-lock.json b/.github/aw/actions-lock.json index 7bc137fc6..c36170282 100644 --- a/.github/aw/actions-lock.json +++ b/.github/aw/actions-lock.json @@ -14,6 +14,11 @@ "repo": "github/gh-aw-actions/setup", "version": "v0.63.0", "sha": "9128d2542bbf1bdfec94dabeaf3e1d3c0d402577" + }, + "github/gh-aw/actions/setup@v0.57.1": { + "repo": "github/gh-aw/actions/setup", + "version": "v0.57.1", + "sha": "36e5751f7c3d40ec9df8f44c0252b7bfabfc4dd6" } } } diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 000000000..4a588fd2c --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,27 @@ +version: 2 +updates: + - package-ecosystem: npm + directory: / + schedule: + interval: weekly + # Keep version-update PRs disabled; these labels also apply to security updates. + open-pull-requests-limit: 0 + labels: + - "type: dependencies" + - "language: javascript" + - package-ecosystem: npm + directory: /website + schedule: + interval: weekly + open-pull-requests-limit: 0 + labels: + - "type: dependencies" + - "language: javascript" + - package-ecosystem: cargo + directory: /apps/gateway + schedule: + interval: weekly + open-pull-requests-limit: 0 + labels: + - "type: dependencies" + - "language: rust" diff --git a/.github/workflows/check-worker-versions.yml b/.github/workflows/check-worker-versions.yml index 0d6d1afec..4d42d510c 100644 --- a/.github/workflows/check-worker-versions.yml +++ b/.github/workflows/check-worker-versions.yml @@ -142,10 +142,10 @@ jobs: env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | - # List open issues with the worker-update label and filter by title prefix. + # List open issues with the type: worker-update label and filter by title prefix. # Using list + jq instead of --search to avoid GitHub search index lag # which can cause duplicate issues when runs happen close together. - ISSUE_JSON=$(gh issue list --state open --label worker-update --json title,url,number \ + ISSUE_JSON=$(gh issue list --state open --label "type: worker-update" --json title,url,number \ --jq '[.[] | select(.title | startswith("chore(${{ matrix.worker }}): update to"))] | .[0] // empty') if [ -n "$ISSUE_JSON" ]; then ISSUE_URL=$(echo "$ISSUE_JSON" | jq -r '.url') @@ -203,7 +203,7 @@ jobs: ISSUE_URL=$(gh issue create \ --title "${{ steps.check.outputs.title }}" \ --body-file /tmp/issue-body.md \ - --label "worker-update") + --label "type: worker-update") echo "issue_url=$ISSUE_URL" >> $GITHUB_OUTPUT - name: Close superseded issue diff --git a/.github/workflows/daily-repo-status.lock.yml b/.github/workflows/daily-repo-status.lock.yml index c84349254..c83fdb957 100644 --- a/.github/workflows/daily-repo-status.lock.yml +++ b/.github/workflows/daily-repo-status.lock.yml @@ -28,13 +28,12 @@ # # Source: githubnext/agentics/workflows/daily-repo-status.md@346204513ecfa08b81566450d7d599556807389f # -# gh-aw-metadata: {"schema_version":"v2","frontmatter_hash":"76b3cf18e33147180c10a0d1a77027cb1cfa8d6f10a743560c55397b8a36dba0","compiler_version":"v0.60.0","strict":true} +# gh-aw-metadata: {"schema_version":"v2","frontmatter_hash":"f11e23adeb5079f5ebf793637f305ba3386f862152fff2f1c8eec0e0533b7905","compiler_version":"v0.60.0","strict":true} name: "Daily Repo Status" "on": schedule: - cron: "47 23 * * *" - # Friendly format: daily (scattered) workflow_dispatch: permissions: {} @@ -331,7 +330,7 @@ jobs: cat > /opt/gh-aw/safeoutputs/tools_meta.json << 'GH_AW_SAFE_OUTPUTS_TOOLS_META_EOF' { "description_suffixes": { - "create_issue": " CONSTRAINTS: Maximum 1 issue(s) can be created. Title will be prefixed with \"[repo-status] \". Labels [\"report\" \"daily-status\"] will be automatically added." + "create_issue": " CONSTRAINTS: Maximum 1 issue(s) can be created. Title will be prefixed with \"[repo-status] \". Labels [\"agentic-workflows\"] will be automatically added." }, "repo_params": {}, "dynamic_tools": [] @@ -1003,7 +1002,7 @@ jobs: GH_AW_ALLOWED_DOMAINS: "api.business.githubcopilot.com,api.enterprise.githubcopilot.com,api.github.com,api.githubcopilot.com,api.individual.githubcopilot.com,api.snapcraft.io,archive.ubuntu.com,azure.archive.ubuntu.com,crl.geotrust.com,crl.globalsign.com,crl.identrust.com,crl.sectigo.com,crl.thawte.com,crl.usertrust.com,crl.verisign.com,crl3.digicert.com,crl4.digicert.com,crls.ssl.com,github.com,host.docker.internal,json-schema.org,json.schemastore.org,keyserver.ubuntu.com,ocsp.digicert.com,ocsp.geotrust.com,ocsp.globalsign.com,ocsp.identrust.com,ocsp.sectigo.com,ocsp.ssl.com,ocsp.thawte.com,ocsp.usertrust.com,ocsp.verisign.com,packagecloud.io,packages.cloud.google.com,packages.microsoft.com,ppa.launchpad.net,raw.githubusercontent.com,registry.npmjs.org,s.symcb.com,s.symcd.com,security.ubuntu.com,telemetry.enterprise.githubcopilot.com,ts-crl.ws.symantec.com,ts-ocsp.ws.symantec.com" GITHUB_SERVER_URL: ${{ github.server_url }} GITHUB_API_URL: ${{ github.api_url }} - GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"create_issue\":{\"close_older_issues\":true,\"labels\":[\"report\",\"daily-status\"],\"max\":1,\"title_prefix\":\"[repo-status] \"},\"missing_data\":{},\"missing_tool\":{}}" + GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"create_issue\":{\"close_older_issues\":true,\"labels\":[\"agentic-workflows\"],\"max\":1,\"title_prefix\":\"[repo-status] \"},\"missing_data\":{},\"missing_tool\":{}}" with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} script: | diff --git a/.github/workflows/daily-repo-status.md b/.github/workflows/daily-repo-status.md index 328754c09..4e219ef67 100644 --- a/.github/workflows/daily-repo-status.md +++ b/.github/workflows/daily-repo-status.md @@ -6,7 +6,8 @@ description: | and project recommendations. on: - schedule: daily + schedule: + - cron: "47 23 * * *" workflow_dispatch: permissions: @@ -32,7 +33,7 @@ safe-outputs: allowed-github-references: [] create-issue: title-prefix: "[repo-status] " - labels: [report, daily-status] + labels: [agentic-workflows] close-older-issues: true source: githubnext/agentics/workflows/daily-repo-status.md@346204513ecfa08b81566450d7d599556807389f --- diff --git a/.github/workflows/daily-test-improver.lock.yml b/.github/workflows/daily-test-improver.lock.yml index ac57519cb..9d099df60 100644 --- a/.github/workflows/daily-test-improver.lock.yml +++ b/.github/workflows/daily-test-improver.lock.yml @@ -33,7 +33,7 @@ # # Source: githubnext/agentics/workflows/daily-test-improver.md@ee86d0ffcb1705d4ee4146e92125227bf9136aae # -# gh-aw-metadata: {"schema_version":"v2","frontmatter_hash":"a7d2783735dd64dcada4437848faab72f12ad046fb0ead8a7197d6cb0656526f","compiler_version":"v0.57.1","strict":true} +# gh-aw-metadata: {"schema_version":"v2","frontmatter_hash":"355fb2f97c519fb48583e605ebbed7f8e38548ad6a4fac6111082043057a8040","compiler_version":"v0.57.1","strict":true} name: "Daily Test Improver" "on": @@ -440,7 +440,7 @@ jobs: cat > /opt/gh-aw/safeoutputs/tools.json << 'GH_AW_SAFE_OUTPUTS_TOOLS_EOF' [ { - "description": "Create a new GitHub issue for tracking bugs, feature requests, or tasks. Use this for actionable work items that need assignment, labeling, and status tracking. For reports, announcements, or status updates that don't require task tracking, use create_discussion instead. CONSTRAINTS: Maximum 4 issue(s) can be created. Title will be prefixed with \"[Test Improver] \". Labels [\"automation\" \"testing\"] will be automatically added.", + "description": "Create a new GitHub issue for tracking bugs, feature requests, or tasks. Use this for actionable work items that need assignment, labeling, and status tracking. For reports, announcements, or status updates that don't require task tracking, use create_discussion instead. CONSTRAINTS: Maximum 4 issue(s) can be created. Title will be prefixed with \"[Test Improver] \". Labels [\"type: automation\" \"topic: testing\"] will be automatically added.", "inputSchema": { "additionalProperties": false, "properties": { @@ -526,7 +526,7 @@ jobs: "name": "add_comment" }, { - "description": "Create a new GitHub pull request to propose code changes. Use this after making file edits to submit them for review and merging. The PR will be created from the current branch with your committed changes. For code review comments on an existing PR, use create_pull_request_review_comment instead. CONSTRAINTS: Maximum 4 pull request(s) can be created. Title will be prefixed with \"[Test Improver] \". Labels [\"automation\" \"testing\"] will be automatically added. PRs will be created as drafts.", + "description": "Create a new GitHub pull request to propose code changes. Use this after making file edits to submit them for review and merging. The PR will be created from the current branch with your committed changes. For code review comments on an existing PR, use create_pull_request_review_comment instead. CONSTRAINTS: Maximum 4 pull request(s) can be created. Title will be prefixed with \"[Test Improver] \". Labels [\"type: automation\" \"topic: testing\"] will be automatically added. PRs will be created as drafts.", "inputSchema": { "additionalProperties": false, "properties": { @@ -1759,7 +1759,7 @@ jobs: GH_AW_ALLOWED_DOMAINS: "*.jsr.io,*.pythonhosted.org,*.vsblob.vsassets.io,adoptium.net,anaconda.org,api.adoptium.net,api.business.githubcopilot.com,api.enterprise.githubcopilot.com,api.foojay.io,api.github.com,api.githubcopilot.com,api.individual.githubcopilot.com,api.npms.io,api.nuget.org,api.snapcraft.io,archive.apache.org,archive.ubuntu.com,azure.archive.ubuntu.com,azuresearch-usnc.nuget.org,azuresearch-ussc.nuget.org,binstar.org,bootstrap.pypa.io,builds.dotnet.microsoft.com,bun.sh,cdn.azul.com,cdn.jsdelivr.net,central.sonatype.com,ci.dot.net,conda.anaconda.org,conda.binstar.org,crates.io,crl.geotrust.com,crl.globalsign.com,crl.identrust.com,crl.sectigo.com,crl.thawte.com,crl.usertrust.com,crl.verisign.com,crl3.digicert.com,crl4.digicert.com,crls.ssl.com,dc.services.visualstudio.com,deb.nodesource.com,deno.land,dist.nuget.org,dl.google.com,dlcdn.apache.org,dot.net,dotnet.microsoft.com,dotnetcli.blob.core.windows.net,download.eclipse.org,download.java.net,download.oracle.com,downloads.gradle-dn.com,esm.sh,files.pythonhosted.org,get.pnpm.io,github.com,googleapis.deno.dev,googlechromelabs.github.io,gradle.org,host.docker.internal,index.crates.io,jcenter.bintray.com,jdk.java.net,json-schema.org,json.schemastore.org,jsr.io,keyserver.ubuntu.com,maven.apache.org,maven.google.com,maven.oracle.com,maven.pkg.github.com,nodejs.org,npm.pkg.github.com,npmjs.com,npmjs.org,nuget.org,nuget.pkg.github.com,nugetregistryv2prod.blob.core.windows.net,ocsp.digicert.com,ocsp.geotrust.com,ocsp.globalsign.com,ocsp.identrust.com,ocsp.sectigo.com,ocsp.ssl.com,ocsp.thawte.com,ocsp.usertrust.com,ocsp.verisign.com,oneocsp.microsoft.com,packagecloud.io,packages.cloud.google.com,packages.microsoft.com,pip.pypa.io,pkgs.dev.azure.com,plugins-artifacts.gradle.org,plugins.gradle.org,ppa.launchpad.net,pypi.org,pypi.python.org,raw.githubusercontent.com,registry.bower.io,registry.npmjs.com,registry.npmjs.org,registry.yarnpkg.com,repo.anaconda.com,repo.continuum.io,repo.gradle.org,repo.grails.org,repo.maven.apache.org,repo.spring.io,repo.yarnpkg.com,repo1.maven.org,s.symcb.com,s.symcd.com,security.ubuntu.com,services.gradle.org,sh.rustup.rs,skimdb.npmjs.com,static.crates.io,static.rust-lang.org,storage.googleapis.com,telemetry.enterprise.githubcopilot.com,telemetry.vercel.com,ts-crl.ws.symantec.com,ts-ocsp.ws.symantec.com,www.java.com,www.microsoft.com,www.npmjs.com,www.npmjs.org,yarnpkg.com" GITHUB_SERVER_URL: ${{ github.server_url }} GITHUB_API_URL: ${{ github.api_url }} - GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"add_comment\":{\"hide_older_comments\":true,\"max\":10,\"target\":\"*\"},\"create_issue\":{\"labels\":[\"automation\",\"testing\"],\"max\":4,\"title_prefix\":\"[Test Improver] \"},\"create_pull_request\":{\"draft\":true,\"labels\":[\"automation\",\"testing\"],\"max\":4,\"max_patch_size\":1024,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"AGENTS.md\"],\"protected_files_policy\":\"fallback-to-issue\",\"protected_path_prefixes\":[\".github/\",\".agents/\"],\"title_prefix\":\"[Test Improver] \"},\"missing_data\":{},\"missing_tool\":{},\"push_to_pull_request_branch\":{\"if_no_changes\":\"warn\",\"max\":4,\"max_patch_size\":1024,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"AGENTS.md\"],\"protected_path_prefixes\":[\".github/\",\".agents/\"],\"target\":\"*\",\"title_prefix\":\"[Test Improver] \"},\"update_issue\":{\"allow_body\":true,\"max\":1,\"target\":\"*\",\"title_prefix\":\"[Test Improver] \"}}" + GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"add_comment\":{\"hide_older_comments\":true,\"max\":10,\"target\":\"*\"},\"create_issue\":{\"labels\":[\"type: automation\",\"topic: testing\"],\"max\":4,\"title_prefix\":\"[Test Improver] \"},\"create_pull_request\":{\"draft\":true,\"labels\":[\"type: automation\",\"topic: testing\"],\"max\":4,\"max_patch_size\":1024,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"AGENTS.md\"],\"protected_files_policy\":\"fallback-to-issue\",\"protected_path_prefixes\":[\".github/\",\".agents/\"],\"title_prefix\":\"[Test Improver] \"},\"missing_data\":{},\"missing_tool\":{},\"push_to_pull_request_branch\":{\"if_no_changes\":\"warn\",\"max\":4,\"max_patch_size\":1024,\"protected_files\":[\"package.json\",\"bun.lockb\",\"bunfig.toml\",\"deno.json\",\"deno.jsonc\",\"deno.lock\",\"global.json\",\"NuGet.Config\",\"Directory.Packages.props\",\"mix.exs\",\"mix.lock\",\"go.mod\",\"go.sum\",\"stack.yaml\",\"stack.yaml.lock\",\"pom.xml\",\"build.gradle\",\"build.gradle.kts\",\"settings.gradle\",\"settings.gradle.kts\",\"gradle.properties\",\"package-lock.json\",\"yarn.lock\",\"pnpm-lock.yaml\",\"npm-shrinkwrap.json\",\"requirements.txt\",\"Pipfile\",\"Pipfile.lock\",\"pyproject.toml\",\"setup.py\",\"setup.cfg\",\"Gemfile\",\"Gemfile.lock\",\"uv.lock\",\"AGENTS.md\"],\"protected_path_prefixes\":[\".github/\",\".agents/\"],\"target\":\"*\",\"title_prefix\":\"[Test Improver] \"},\"update_issue\":{\"allow_body\":true,\"max\":1,\"target\":\"*\",\"title_prefix\":\"[Test Improver] \"}}" GH_AW_CI_TRIGGER_TOKEN: ${{ secrets.GH_AW_CI_TRIGGER_TOKEN }} with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/daily-test-improver.md b/.github/workflows/daily-test-improver.md index 426199e71..05f8d16f0 100644 --- a/.github/workflows/daily-test-improver.md +++ b/.github/workflows/daily-test-improver.md @@ -11,7 +11,8 @@ description: | Always thoughtful, quality-focused, and mindful of test maintainability. on: - schedule: daily + schedule: + - cron: "3 6 * * *" workflow_dispatch: slash_command: name: test-assist @@ -38,7 +39,7 @@ safe-outputs: create-pull-request: draft: true title-prefix: "[Test Improver] " - labels: [automation, testing] + labels: ["type: automation", "topic: testing"] max: 4 protected-files: fallback-to-issue push-to-pull-request-branch: @@ -47,7 +48,7 @@ safe-outputs: max: 4 create-issue: title-prefix: "[Test Improver] " - labels: [automation, testing] + labels: ["type: automation", "topic: testing"] max: 4 update-issue: target: "*" @@ -209,7 +210,7 @@ Always do Task 7 (Update Monthly Activity Summary Issue) every run. In all comme ### Task 5: Comment on Testing Issues -1. List open issues mentioning tests, coverage, or with `testing` label. Resume from memory's backlog cursor. +1. List open issues mentioning tests, coverage, or with the `topic: testing` label. Resume from memory's backlog cursor. 2. For each issue (save cursor in memory): prioritize issues that have never received a Test Improver comment. 3. If you have something insightful and actionable to say: - Suggest testing approaches or strategies @@ -253,7 +254,7 @@ Always do Task 7 (Update Monthly Activity Summary Issue) every run. In all comme Maintain a single open issue titled `[Test Improver] Monthly Activity {YYYY}-{MM}` as a rolling summary of all Test Improver activity for the current month. -1. Search for an open `[Test Improver] Monthly Activity` issue with label `testing`. If it's for the current month, update it. If for a previous month, close it and create a new one. Read any maintainer comments - they may contain instructions or priorities; note them in memory. +1. Search for an open `[Test Improver] Monthly Activity` issue with label `topic: testing`. If it's for the current month, update it. If for a previous month, close it and create a new one. Read any maintainer comments - they may contain instructions or priorities; note them in memory. 2. **Issue body format** - use **exactly** this structure: ```markdown diff --git a/.github/workflows/worker-version-upgrade.lock.yml b/.github/workflows/worker-version-upgrade.lock.yml index 99eb7ab1c..0691fc3a1 100644 --- a/.github/workflows/worker-version-upgrade.lock.yml +++ b/.github/workflows/worker-version-upgrade.lock.yml @@ -24,13 +24,13 @@ # by the check-worker-versions workflow. Copilot reads the issue body, updates # the versions.env file, runs integration tests, and opens a PR. # -# gh-aw-metadata: {"schema_version":"v3","frontmatter_hash":"0e2e0e58f90970c8881e8c9bb2cb9f9d17260feb95b5f9d57288338c3b478043","compiler_version":"v0.63.0","strict":true,"agent_id":"copilot"} +# gh-aw-metadata: {"schema_version":"v3","frontmatter_hash":"8da589511e1413ea0d84ab82a748d2a1cb11cddec70861ec5a55932d28afa462","compiler_version":"v0.63.0","strict":true,"agent_id":"copilot"} name: "Worker Version Upgrade" "on": issues: # names: # Label filtering applied via job conditions - # - worker-update # Label filtering applied via job conditions + # - "type: worker-update" # Label filtering applied via job conditions types: - opened - edited @@ -39,8 +39,9 @@ name: "Worker Version Upgrade" # LABELS: ${{ toJSON(github.event.issue.labels.*.name) }} # id: label_check # if: github.event_name != 'workflow_dispatch' - # name: Check worker-update label - # run: echo "$LABELS" | grep -q '"worker-update"' + # name: Check worker update label + # run: | + # echo "$LABELS" | grep -q '"type: worker-update"' workflow_dispatch: inputs: aw_context: @@ -998,10 +999,11 @@ jobs: setupGlobals(core, github, context, exec, io); const { main } = require('${{ runner.temp }}/gh-aw/actions/check_membership.cjs'); await main(); - - name: Check worker-update label + - name: Check worker update label id: label_check if: github.event_name != 'workflow_dispatch' - run: echo "$LABELS" | grep -q '"worker-update"' + run: | + echo "$LABELS" | grep -q '"type: worker-update"' env: LABELS: ${{ toJSON(github.event.issue.labels.*.name) }} diff --git a/.github/workflows/worker-version-upgrade.md b/.github/workflows/worker-version-upgrade.md index 5e78e95f7..1fa463a61 100644 --- a/.github/workflows/worker-version-upgrade.md +++ b/.github/workflows/worker-version-upgrade.md @@ -7,17 +7,18 @@ description: | on: issues: types: [opened, edited] - names: [worker-update] + names: ["type: worker-update"] workflow_dispatch: # Workaround: gh-aw compiler bug — `names:` is commented out in the lock file # and no label condition is injected. Use on.steps to enforce label filtering. steps: - - name: Check worker-update label + - name: Check worker update label id: label_check if: github.event_name != 'workflow_dispatch' env: LABELS: ${{ toJSON(github.event.issue.labels.*.name) }} - run: echo "$LABELS" | grep -q '"worker-update"' + run: | + echo "$LABELS" | grep -q '"type: worker-update"' if: github.event_name == 'workflow_dispatch' || needs.pre_activation.outputs.label_check_result == 'success' diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 6d0c0b226..691467f69 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -278,8 +278,65 @@ without a response**. Close it **two weeks after the reminder (four weeks total) still no response, making clear that the contributor can resume later. Do not close PRs under this rule when they are waiting on the team. -As a team follow-up, create a `waiting-on-author` label to track these PRs. Once available, the PR -owner applies it when requesting a response and removes it when the contributor responds. +The PR owner applies `status: waiting` when requesting a contributor response and removes it when +the contributor responds. State who owes the next action in a comment; the label alone must not +trigger the closure policy, particularly when a PR is waiting on the team. + +## Repository labels + +Use the existing `category: value` labels for issue and PR triage. Check the +[live label list](https://github.com/microsoft/scope/labels) before applying labels; +do not recreate retired names or the migration-only `author:` labels. +Keep `good first issue` and `help wanted` unprefixed for contribution discovery. + +Automations depend on these exact names: + +| Consumer | Labels | +| --- | --- | +| Worker version checker and upgrade workflow | `type: worker-update` | +| Test Improver issues, PRs, and monthly-summary searches | `type: automation`, `topic: testing` | +| Daily repository status reports | `agentic-workflows` | +| Dependabot | `type: dependencies`, plus `language: javascript` or `language: rust` | + +Use `area: reporting` for Scope's benchmark reporting component, not daily repository activity. +Worker upgrade routing uses `type: worker-update`, not the broader `area: worker`. + +### Agentic Workflows system-label exception + +The pinned GitHub Agentic Workflows runtimes hard-code the unprefixed `agentic-workflows` +label when searching for and creating failure reports, no-op tracking issues, and PR fallback +issues. This is a machine-managed compatibility exception to the namespaced label convention. + +Before relying on these workflows after a label migration, a maintainer must ensure +`agentic-workflows` exists and is applied to existing workflow tracking issues that were renamed, +especially `[aw] No-Op Runs` and `[aw] ... failed` issues. Otherwise the runtime can miss existing +trackers and attempt duplicate reports. Keep this exact name until every active runtime supports +a replacement for both lookups and writes. +Changing `safe-outputs` label lists alone does not change these built-in handlers. +Repository configuration does not create or backfill this label automatically. + +### Updating label-dependent configuration + +Update both the label filters and label writes in `.github/workflows/check-worker-versions.yml`, +the agentic workflow `.md` frontmatter, and any label searches in their prompts. +Regenerate the corresponding `.lock.yml` files with `gh aw compile`; do not edit generated YAML +by hand. Use each file's recorded compiler version to avoid unrelated runtime upgrades: + +| Workflow | Compiler | +| --- | --- | +| `daily-test-improver` | `v0.57.1` | +| `daily-repo-status` | `v0.60.0` | +| `worker-version-upgrade` | `v0.63.0` | + +The daily schedules are explicit cron expressions preserving their existing UTC execution times. +Review changes to `.github/aw/actions-lock.json` and generated workflow permissions, triggers, +action pins, and handler configuration before merging. + +`.github/dependabot.yml` specifies namespaced labels for the root pnpm workspace, the separate +website package, and the Rust gateway. Each entry has `open-pull-requests-limit: 0` to keep +version-update PRs disabled; the required schedule does not enable those PRs. These labels also +apply to security-update PRs when security updates are enabled in repository settings. This file +does not enable security updates or change live labels. ## Third-party notices