Skip to content

updated to awf 0.27.2#38660

Merged
pelikhan merged 2 commits into
mainfrom
firewall-0.27.2
Jun 11, 2026
Merged

updated to awf 0.27.2#38660
pelikhan merged 2 commits into
mainfrom
firewall-0.27.2

Conversation

@pelikhan

@pelikhan pelikhan commented Jun 11, 2026

Copy link
Copy Markdown
Collaborator


✨ PR Review Safe Output Test - Run 27361655884

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · 94.7 AIC · ⌖ 25.7 AIC ·

Copilot AI review requested due to automatic review settings June 11, 2026 16:25
@pelikhan pelikhan added the smoke label Jun 11, 2026
@github-actions

github-actions Bot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

🚀 Smoke Antigravity MISSION COMPLETE! Antigravity has spoken. ✨

@github-actions

github-actions Bot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

🚀 Smoke Pi MISSION COMPLETE! Pi delivered. 🥧

@github-actions

github-actions Bot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

✅ All tools validated successfully! Agent Container Smoke Test confirms agent container is ready.

@github-actions

github-actions Bot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

⚠️ Smoke Gemini failed. Gemini encountered unexpected challenges...

@github-actions

github-actions Bot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

@github-actions

github-actions Bot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

🎬 THE ENDSmoke Claude MISSION: ACCOMPLISHED! The hero saves the day! ✨

@github-actions

Copy link
Copy Markdown
Contributor

📰 BREAKING: Smoke Copilot - AOAI (apikey) is now investigating this pull request. Sources say the story is developing...

@github-actions

Copy link
Copy Markdown
Contributor

📰 BREAKING: Smoke Copilot is now investigating this pull request. Sources say the story is developing...

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the repository’s default gh-aw-firewall (AWF) version to v0.27.2 and refreshes the generated/pinned artifacts that depend on that version (container image SHA pins and compiled *.lock.yml workflows).

Changes:

  • Bump DefaultFirewallVersion from v0.27.1 to v0.27.2.
  • Add container image pin entries for AWF 0.27.2 (agent, api-proxy, cli-proxy, squid) to the action/container pin datasets.
  • Regenerate compiled *.lock.yml workflows to reference AWF v0.27.2 (install script arg, schema URL, container digests/pinned images).
Show a summary per file
File Description
pkg/constants/version_constants.go Bumps the default AWF version constant to v0.27.2.
pkg/workflow/data/action_pins.json Adds AWF 0.27.2 container digest/pinned-image entries used by workflow compilation.
pkg/actionpins/data/action_pins.json Mirrors the AWF 0.27.2 container digest/pinned-image additions in the actionpins dataset.
.github/aw/actions-lock.json Adds AWF 0.27.2 container digest/pinned-image entries for workflow locking/pinning.
.github/workflows/test-workflow.lock.yml Regenerates locked workflow to use AWF v0.27.2 (schema URL, install arg, pinned images).
.github/workflows/smoke-ci.lock.yml Regenerates locked workflow to use AWF v0.27.2 (schema URL, install arg, pinned images).
.github/workflows/hippo-embed.lock.yml Regenerates locked workflow to use AWF v0.27.2 (schema URL, install arg, pinned images).
.github/workflows/firewall.lock.yml Regenerates locked workflow to use AWF v0.27.2 (schema URL, install arg, pinned images).
.github/workflows/example-permissions-warning.lock.yml Regenerates locked workflow to use AWF v0.27.2 (schema URL, install arg, pinned images).
.github/workflows/daily-malicious-code-scan.lock.yml Regenerates locked workflow to use AWF v0.27.2 (schema URL, install arg, pinned images).
.github/workflows/codex-github-remote-mcp-test.lock.yml Regenerates locked workflow to use AWF v0.27.2 (schema URL, install arg, pinned images).
.github/workflows/bot-detection.lock.yml Regenerates locked workflow to use AWF v0.27.2 (schema URL, install arg, pinned images).
.github/workflows/ai-moderator.lock.yml Regenerates locked workflow to use AWF v0.27.2 (schema URL, install arg, pinned images).
.github/workflows/agentic-token-optimizer.lock.yml Regenerates locked workflow to use AWF v0.27.2, including cli-proxy image pin updates.
.github/workflows/ace-editor.lock.yml Regenerates locked workflow to use AWF v0.27.2 (schema URL, install arg, pinned images).

Copilot's findings

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 39/258 changed files
  • Comments generated: 0

This was referenced Jun 11, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Agent Container Tool Check

Tool Status Version
bash 5.2.21
sh available
git 2.54.0
jq 1.7
yq v4.53.3
curl 8.5.0
gh 2.93.0
node v22.22.3
python3 3.11.15 (PyPy)
go 1.24.13
java available
dotnet 10.0.300

Result: 12/12 tools available ✅

Overall Status: PASS

🔧 Tool validation by Agent Container Smoke Test · 30.7 AIC · ⌖ 12.6 AIC ·

@github-actions

Copy link
Copy Markdown
Contributor

✅ smoke-ci: safeoutputs CLI comment + comment-memory run (27361772545)

Generated by 🧪 Smoke CI for issue #38660 ·

@github-actions

Copy link
Copy Markdown
Contributor

Comment Memory

CI lights the path
Green checks bloom at dawn
Quiet bots still sing

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

Generated by 🧪 Smoke CI for issue #38660 ·

@github-actions

Copy link
Copy Markdown
Contributor

Smoke test: PASS
PRs: #38630, #38622
1 ✅ 2 ✅ 3 ✅ 4 ⚪ 5 ✅ 6 ✅ 7 ✅ 8 ✅ 9 ✅ 10 ⚪

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex · 29.3 AIC · ⌖ 8.26 AIC ·

@github-actions

Copy link
Copy Markdown
Contributor

Comment Memory

Silent smoke drifts up
Fresh caches hum beneath the build
GitHub waits in light

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex · 29.3 AIC · ⌖ 8.26 AIC ·

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test 27361686786: FAIL

  1. GitHub MCP ✅
  2. mcpscripts-gh ❌
  3. Serena CLI ❌
  4. Playwright CLI ❌
  5. Web fetch ✅
  6. File + bash ✅
  7. Build ✅
    9-15. Other tests ❌
    Author: @pelikhan Assignees: @

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot - AOAI (apikey) · 60.4 AIC · ⌖ 7.61 AIC ·

1 similar comment
@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test 27361686786: FAIL

  1. GitHub MCP ✅
  2. mcpscripts-gh ❌
  3. Serena CLI ❌
  4. Playwright CLI ❌
  5. Web fetch ✅
  6. File + bash ✅
  7. Build ✅
    9-15. Other tests ❌
    Author: @pelikhan Assignees: @

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot - AOAI (apikey) · 60.4 AIC · ⌖ 7.61 AIC ·

@pelikhan pelikhan merged commit 9c481b8 into main Jun 11, 2026
29 checks passed
@pelikhan pelikhan deleted the firewall-0.27.2 branch June 11, 2026 16:39
@github-actions

Copy link
Copy Markdown
Contributor

🤖 Smoke Test: Claude — Run 27361655884

Core #1-12: ✅ all passed (MCP, gh CLI, build, Playwright, Tavily, file/bash, discussion, AW status, Slack, code-scan, check-run)
PR review #13-19: ✅ update, ✅ review comments, ✅ submit review, ⚠️ resolve thread (none unresolved), ✅ add reviewer, ✅ push, ⚠️ close PR (no safe test PR)

Overall: PARTIAL (2 skipped, 0 failed)

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · 94.7 AIC · ⌖ 25.7 AIC ·

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💥 Automated smoke test review - all systems nominal!

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · 94.7 AIC · ⌖ 25.7 AIC

"digest": "sha256:55149fa2daf8fa8afa2803f2ac1a3534591a7c96f173ee2aec9545fbe67305df",
"pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.1@sha256:55149fa2daf8fa8afa2803f2ac1a3534591a7c96f173ee2aec9545fbe67305df"
},
"ghcr.io/github/gh-aw-firewall/agent:0.27.2": {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Smoke test review: new 0.27.2 agent image pin added — looks consistent with existing entries. 👍

"digest": "sha256:2802437f05830336ea3ae8639f628776608d14d95b5b3cf30f161eb505e29752",
"pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.1@sha256:2802437f05830336ea3ae8639f628776608d14d95b5b3cf30f161eb505e29752"
},
"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.2": {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Smoke test review: api-proxy 0.27.2 digest pinned correctly. Nit: consider grouping image entries by component for readability.

@github-actions

Copy link
Copy Markdown
Contributor

updated to awf 0.27.2
T1❌ T2✅ T3✅ T4✅ T5✅
T6✅ T7✅ T8✅ T9✅ T10✅
T11✅ T12✅ T13✅ T14✅ T15✅
Overall: FAIL
Author: @pelikhan
Assignees: none

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot · 335.6 AIC · ⌖ 10.7 AIC ·

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants