chore: upgrade gh-aw to v0.86.3 - #7388
Conversation
Upgrade the gh-aw pre-release and recompile all agentic workflows. Migrate Azure OIDC credentials to engine auth configuration. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
✅ Coverage Check PassedOverall Coverage
📁 Per-file Coverage Changes (1 files)
Coverage comparison generated by |
There was a problem hiding this comment.
Pull request overview
Upgrades gh-aw to v0.86.3, recompiles representative agentic workflows, and migrates Azure Entra authentication into engine.auth.
Changes:
- Updates gh-aw actions, metadata, engines, and AWF images.
- Applies local AWF build post-processing to generated workflows.
- Migrates Azure OIDC configuration, but generated credentials are missing.
Show a summary per file
| File | Description |
|---|---|
.github/workflows/smoke-gemini.lock.yml |
Recompiles Gemini smoke workflow. |
.github/workflows/smoke-copilot-byok-aoai-entra.md |
Moves Azure OIDC settings into engine.auth. |
.github/workflows/smoke-cloud-hypervisor.lock.yml |
Recompiles Copilot microVM smoke workflow. |
.github/workflows/smoke-cloud-hypervisor-codex.lock.yml |
Recompiles Codex microVM smoke workflow. |
.github/workflows/smoke-cloud-hypervisor-claude.lock.yml |
Recompiles Claude microVM smoke workflow. |
.github/workflows/smoke-cloud-hypervisor-build-test.lock.yml |
Recompiles microVM build test. |
.github/workflows/smoke-claude.lock.yml |
Recompiles Claude smoke workflow. |
.github/workflows/firewall-issue-dispatcher.lock.yml |
Recompiles issue dispatcher workflow. |
.github/workflows/contribution-check.lock.yml |
Recompiles contribution checks. |
.github/workflows/agentics-maintenance.yml |
Updates maintenance action and CLI pins. |
.github/aw/actions-lock.json |
Updates action and container-image locks. |
Review details
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- Files reviewed: 29/67 changed files
- Comments generated: 1
- Review effort level: Balanced
Use gh-aw v0.86.3 for the supply chain workflow so cloud-hypervisor workflows compile. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
✅ Copilot review passed with no inline comments. @lpcox Add the |
Rebuild GitHub CLI v2.97.0 with Go 1.26.6 and remove the unused Pebble binary. Scope Docker CLI exceptions to network paths unreachable through the enclave Unix socket. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
✅ Smoke Claude passed
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 Warning Firewall blocked 3 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "msfeed2.pkgs.visualstudio.com"
- "msfeed25.pkgs.visualstudio.com"
- "registry.npmjs.org"See Network Configuration for more information.
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
✅ Security Guard completed successfully! Security review complete for PR #7388 (chore: upgrade gh-aw to v0.86.3). Three security-relevant Dockerfiles were identified (containers/agent/Dockerfile, containers/cli-proxy/Dockerfile, containers/enclave/Dockerfile), all showing no textual changes (+0/-0). No firewall rule modifications, capability changes, domain ACL expansions, seccomp relaxations, or security-weakening code detected. All other changed files are workflow lock files and configuration updates. PR passes security review.
|
|
✅ Smoke Copilot BYOK AOAI (api-key) completed. Copilot AOAI BYOK (api-key) mode operational. 🔓
|
|
📰 VERDICT: Smoke Docker Sbx has concluded. All systems operational. This is a developing story. 🎤
|
|
✅ Contribution Check completed successfully! Contribution review complete: no guideline issues that warrant a comment. The PR description is clear, includes testing, and the changes are organized in the expected generated workflow/config files.
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"See Network Configuration for more information.
|
|
✅ Build Test Suite completed successfully!
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
🔌 Smoke Services — Service connectivity was cancelled
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
This comment has been minimized.
This comment has been minimized.
Keep runner-level Azure identity bindings while retaining engine auth metadata. This lets the compiler exclude both IDs from the agent container. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
✅ Build Test Suite completed successfully!
|
|
❌ Contribution Check was cancelled. Please review the logs for details.
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
Chroot tests failed Smoke Chroot was cancelled - See logs for details.
|
|
❌ Security Guard failed. Please review the logs for details.
|
|
📰 VERDICT: Smoke Docker Sbx has concluded. All systems operational. This is a developing story. 🎤
|
|
✅ Smoke Copilot BYOK AOAI (Entra) completed. Copilot AOAI BYOK (Entra) mode operational. 🔓
|
Smoke Test: Copilot BYOK (Direct) Mode ✅ PASS
Running in direct BYOK mode (COPILOT_PROVIDER_API_KEY)
|
Smoke Test: Claude Engine Validation
Overall result: PASS
|
|
EGRESS_RESULT allow=pass deny=pass ✅ Allowed domain (api.github.com) reachable — Overall: PASS cc @lpcox Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"See Network Configuration for more information.
|
|
Smoke Test: Copilot Engine
Overall: PASS ✅ cc @lpcox
|
|
chore: upgrade gh-aw to v0.86.3
Running in direct BYOK mode (COPILOT_PROVIDER_API_KEY + COPILOT_PROVIDER_BASE_URL) via api-proxy → Azure OpenAI (Foundry, o4-mini-aw) Overall: PASS cc @lpcox
|
|
chore: upgrade gh-aw to v0.86.3
Running in direct BYOK mode (AWF_AUTH_TYPE=github-oidc + AWF_AUTH_AZURE_* + COPILOT_PROVIDER_BASE_URL) via api-proxy → Azure OpenAI (Foundry, o4-mini-aw) authenticated via Microsoft Entra Overall: PASS
|
|
Reviewed PRs: [docs] auth: auth: document cli-proxy-egress relay for DIFC credential isolation under network-isolation Warning Firewall blocked 3 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "msfeed2.pkgs.visualstudio.com"
- "msfeed25.pkgs.visualstudio.com"
- "registry.npmjs.org"See Network Configuration for more information.
|
🏗️ Build Test Suite Results
Overall: 7/8 ecosystems passed — FAIL (C++ failed) ❌ Failure Details — C++ (fmt, json)CMake configuration failed for both Root cause: Note: This run was triggered by pull request #7388. Since not all ecosystems passed, the
|
Smoke Test: API Proxy OpenTelemetry Tracing — Results
Overall: All 5 scenarios passed. ✅
|
🔥 Smoke Test: Docker Sbx Validation
Recent merged PRs: #7387, #7370 Overall: PASS
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
Smoke Test: Services Connectivity — FAIL
Overall: FAIL —
|
Summary
engine.authTesting
npm test(305 suites, 4,806 tests passed)