Skip to content

v0.89.21

Latest

Choose a tag to compare

@github-actions github-actions released this 23 Sep 20:29
· 130 commits to main since this release
Immutable release. Only release title and notes can be modified.
c353937

🌟 Release Highlights

This release brings native web-search support for the Copilot engine, more flexible reusable-workflow failure reporting, and hardened safe-outputs checkout detection.

✨ What's New

  • Native web-search on the Copilot engine β€” tools: web-search: now compiles to Copilot's built-in web_search tool (--allow-tool web_search) instead of producing a compile warning, making web search usable even in repos without GitHub tooling (e.g. Azure DevOps-hosted). See Web Search reference. (#62957)
  • Dynamic failure-issue-repo for reusable workflows β€” safe-outputs.failure-issue-repo now accepts ${{ inputs.* }} expressions, matching existing support for report-failure-as-issue and report-failed-jobs, so reusable (workflow_call) workflows can route failure issues per caller without patching the compiled lock file. (#62945)
  • Gateway steering events in audit output β€” gh aw audit now surfaces token_steering and timeout_steering events (type, message, timestamp) as gateway_steering_events in both JSON and console output, making it easier to see when runs are approaching AI Credit or time limits. (#62943)

πŸ› Bug Fixes & Improvements

  • Fixed cancelled AIC component accounting β€” cancelled compiler-owned component jobs are now only counted as zero AI Credits when GitHub job metadata proves execution never started; jobs with assigned runners, steps, or incomplete metadata are still accounted for correctly. (#62984)
  • Safe-outputs checkout detection fixed for nested repos β€” the find_repo_checkout git-scan fallback now trusts scanned repositories cloned via a steps: entry or manual actions/checkout, fixing a regression where the containerized safe-outputs MCP server (different UID) couldn't read nested checkouts due to git's safe.directory trust not propagating beyond GITHUB_WORKSPACE. (#62944)

πŸ“š Documentation

  • Stale lock-file detection guidance β€” new docs explain how to detect stale/missing compiled .lock.yml files via gh aw list --json for CI enforcement, plus remediation steps for contributors. (#62947)
  • Portable OTLP helper paths β€” OpenTelemetry/qmd examples now resolve the helper via RUNNER_TEMP instead of a hardcoded /tmp, for portability across runner environments. (#62940)

πŸ”§ Internal

  • Updated GitHub Actions versions and refreshed parser/repoutil/semverutil/sliceutil spec extractions.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • o205451.ingest.us.sentry.io

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "o205451.ingest.us.sentry.io"

See Network Configuration for more information.

Generated by πŸš€ Release Β· copilot Β· auto Β· 21.7 AIC Β· ⊞ 11.6K


What's Changed

  • [spec-extractor] Update package specifications for parser, repoutil, semverutil, sliceutil by @github-actions[bot] in #62922
  • [actions] Update GitHub Actions versions - 2026-09-23 by @github-actions[bot] in #62899
  • Use portable path for OTLP helper guidance by @pelikhan with @Copilot in #62940
  • [blog] Agent of the Day – 2026-09-23 by @github-actions[bot] in #62969
  • Allow ${{ inputs.* }} expressions in safe-outputs.failure-issue-repo for reusable workflows by @pelikhan with @Copilot in #62945
  • Document stale agentic workflow lock detection by @pelikhan with @Copilot in #62947
  • Support native web-search on the Copilot engine by @pelikhan with @Copilot in #62957
  • Fix cancelled daily AIC component accounting by @lpcox in #62984
  • Report gateway steering events in audit output by @pelikhan with @Copilot in #62943

Full Changelog: v0.89.20...v0.89.21