Skip to content

Bump default AWF firewall to v0.25.49 and refresh compiled lockfiles#33124

Merged
pelikhan merged 4 commits into
mainfrom
copilot/bump-firewall-to-v02549
May 18, 2026
Merged

Bump default AWF firewall to v0.25.49 and refresh compiled lockfiles#33124
pelikhan merged 4 commits into
mainfrom
copilot/bump-firewall-to-v02549

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented May 18, 2026

This updates gh-aw’s default AWF firewall version from v0.25.46 to v0.25.49 and regenerates compiled workflow lock artifacts so runtime manifests and embedded AWF references stay aligned with the new default.

  • Version pin update

    • Updated pkg/constants/version_constants.go:
      • DefaultFirewallVersionv0.25.49
    • Left AWF feature gate minimums (AWF*MinVersion) unchanged.
  • Compiled workflow artifact refresh

    • Recompiled workflow lockfiles (.github/workflows/*.lock.yml) so generated AWF install args, schema URLs, and firewall container image tags now resolve to 0.25.49.
  • Release metadata

    • Added a patch changeset entry documenting the AWF default-version bump.
// pkg/constants/version_constants.go
const DefaultFirewallVersion Version = "v0.25.49"


✨ PR Review Safe Output Test - Run 26058026496

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · ● 4.7M ·

Copilot AI linked an issue May 18, 2026 that may be closed by this pull request
4 tasks
@github-actions github-actions Bot mentioned this pull request May 18, 2026
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Copilot AI changed the title [WIP] Bump default AWF firewall version to v0.25.49 Bump default AWF firewall to v0.25.49 and refresh compiled lockfiles May 18, 2026
Copilot finished work on behalf of lpcox May 18, 2026 19:02
Copilot AI requested a review from lpcox May 18, 2026 19:02
@lpcox lpcox marked this pull request as ready for review May 18, 2026 19:15
Copilot AI review requested due to automatic review settings May 18, 2026 19:15
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Bumps the default AWF firewall version from v0.25.46 to v0.25.49 and refreshes all compiled workflow lockfiles to match.

Changes:

  • Updated DefaultFirewallVersion constant in pkg/constants/version_constants.go to v0.25.49.
  • Regenerated all .github/workflows/*.lock.yml artifacts so manifests, image tags, AWF install args, and schema URLs reference 0.25.49.
  • Added a patch changeset entry documenting the bump.
Show a summary per file
File Description
pkg/constants/version_constants.go Updates DefaultFirewallVersion to v0.25.49.
.changeset/patch-upgrade-awf-firewall-v0-25-49.md Adds patch changeset for the AWF default-version bump.
.github/workflows/*.lock.yml (17 files) Regenerated lockfiles updating firewall container tags, AWF binary install args, schema URLs, and GH_AW_INFO_AWF_VERSION from 0.25.46 to 0.25.49.

Copilot's findings

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 65/233 changed files
  • Comments generated: 0

@lpcox
Copy link
Copy Markdown
Collaborator

lpcox commented May 18, 2026

@copilot merge main

…-to-v02549

# Conflicts:
#	.github/workflows/pr-sous-chef.lock.yml

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Copy link
Copy Markdown
Contributor Author

Copilot AI commented May 18, 2026

@copilot merge main

Merged main into this branch in commit ddc295c.

Copilot finished work on behalf of lpcox May 18, 2026 19:34
@github-actions
Copy link
Copy Markdown
Contributor

@copilot please ask reviewers to re-check after the refresh.

Generated by 👨‍🍳 PR Sous Chef ·

@lpcox lpcox added the smoke label May 18, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 18, 2026

Smoke OTEL completed successfully!

@github-actions github-actions Bot removed the smoke label May 18, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 18, 2026

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 18, 2026

🚀 Smoke Gemini MISSION COMPLETE! Gemini has spoken. ✨

Caution

agentic threat detected
Threat detection flagged this output in warn mode. Manual review is REQUIRED before any follow-up automation.

Details

The threat detection results could not be parsed.

Review the workflow run logs for details.

@github-actions
Copy link
Copy Markdown
Contributor

📰 BREAKING: Smoke Copilot is now investigating this pull request. Sources say the story is developing...

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 18, 2026

🎬 THE ENDSmoke Claude MISSION: ACCOMPLISHED! The hero saves the day! ✨

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 18, 2026

⚠️ Smoke Pi failed. Pi encountered unexpected challenges...

@github-actions
Copy link
Copy Markdown
Contributor

Agent Container Tool Check

Tool Status Version
bash 5.2.21
sh available
git 2.54.0
jq 1.7
yq v4.53.2
curl 8.5.0
gh 2.92.0
node v22.22.2
python3 3.14.5
go 1.24.13
java openjdk 21.0.11
dotnet 10.0.300

Result: 12/12 tools available ✅

Overall Status: PASS

🔧 Tool validation by Agent Container Smoke Test · ● 1.7M ·

@github-actions
Copy link
Copy Markdown
Contributor

Caution

agentic threat detected
Threat detection flagged this output in warn mode. Manual review is REQUIRED before any follow-up automation.

Details

The threat detection results could not be parsed.

Review the workflow run logs for details.

Smoke Test Results

  • GitHub MCP: ✅
  • Web Fetch: ✅
  • File Writing: ✅
  • Bash Tool: ✅
  • Build gh-aw: ❌

Overall Status: FAIL

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • localhost

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "localhost"

See Network Configuration for more information.

Smoke Gemini — Powered by Gemini ·

@github-actions
Copy link
Copy Markdown
Contributor

Smoke Codex 26058026452: FAIL
PRs: #33116 fix: use COPILOT_DUMMY_BYOK indirection to suppress secret-scanner false positives on lock files; #33089 Match agent failure issues by stored metadata instead of title alone
✅ GitHub MCP, Serena, Playwright, file/bash, build, comment memory, cache memory, set_issue_field
❌ Web fetch MCP unavailable in this session
Run: https://github.com/github/gh-aw/actions/runs/26058026452

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex · ● 7.4M ·

@github-actions
Copy link
Copy Markdown
Contributor

Comment Memory

Smoke curls through build logs
Quiet tools wake and answer
Green checks mark the run

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex · ● 7.4M ·

@github-actions
Copy link
Copy Markdown
Contributor

💥 Smoke Test: Claude — Run §26058026496

Core (#1#12): ✅✅✅✅✅✅✅✅✅✅✅✅
PR Review (#13#19): ✅ ✅ ✅ ⚠️(16) ✅ ✅ ⚠️(19)

Overall: ⚠️ PARTIAL — all non-skipped tests passed; #16 & #19 skipped (no unresolved threads / no safe test PR).

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · ● 4.7M ·

Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💥 Automated smoke test review - all systems nominal!

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

💥 [THE END] — Illustrated by Smoke Claude · ● 4.7M

@@ -0,0 +1,5 @@
---
"gh-aw": patch
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Smoke test review comment: changeset header looks correct — gh-aw: patch is the right semver bump for a default version bump.

"gh-aw": patch
---

Bumped the default AWF firewall version to `v0.25.49`.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Smoke test review comment: changeset summary clearly states the firewall version bump — nice and explicit.

@github-actions
Copy link
Copy Markdown
Contributor

🎉 Smoke test run §26058026329 says hello! All systems green — Copilot, Serena, Playwright, builds. The robots are thriving! 🤖✨

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot · ● 13.7M ·

@github-actions
Copy link
Copy Markdown
Contributor

🎊 Hello from the smoke test run §26058026329! All tests passed with flying colors. The agents are dancing, the builds are green, and the robots are celebrating. 🤖🎉 Thanks for being a great test subject, discussion!

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot · ● 13.7M ·

@github-actions
Copy link
Copy Markdown
Contributor

Comment Memory

Code runs in the dark,
Assertions light the pathway—
Green means all is well.

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot · ● 13.7M ·

Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Smoke test review: Lock file bump to v0.25.49 looks clean. New checkout config with full PR ref fetching is a good improvement for diff-based workflows. No concerns.

Warning

Firewall blocked 6 domains

The following domains were blocked by the firewall during workflow execution:

  • accounts.google.com
  • android.clients.google.com
  • clients2.google.com
  • contentautofill.googleapis.com
  • safebrowsingohttpgateway.googleapis.com
  • www.google.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "accounts.google.com"
    - "android.clients.google.com"
    - "clients2.google.com"
    - "contentautofill.googleapis.com"
    - "safebrowsingohttpgateway.googleapis.com"
    - "www.google.com"

See Network Configuration for more information.

📰 BREAKING: Report filed by Smoke Copilot · ● 13.7M

Comment thread .github/workflows/pr-sous-chef.lock.yml Outdated
@@ -1,5 +1,5 @@
# gh-aw-metadata: {"schema_version":"v3","frontmatter_hash":"20e519f90372e13b267ae10e1b57c90bd77480dee8f18c90ebe1c3905b354311","compiler_version":"v0.74.4","strict":true,"agent_id":"copilot","agent_model":"gpt-5-mini"}
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lock file correctly bumped to gh-aw-firewall v0.25.49 across all container images. The compiler_version field is a new addition — nice for traceability.

@github-actions
Copy link
Copy Markdown
Contributor

📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤

@pelikhan pelikhan merged commit 0153b74 into main May 18, 2026
7 checks passed
@pelikhan pelikhan deleted the copilot/bump-firewall-to-v02549 branch May 18, 2026 20:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bump firewall to v0.25.49

4 participants