·
130 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
π Release Highlights
This release brings native web-search support for the Copilot engine, more flexible reusable-workflow failure reporting, and hardened safe-outputs checkout detection.
β¨ What's New
- Native web-search on the Copilot engine β
tools: web-search:now compiles to Copilot's built-inweb_searchtool (--allow-tool web_search) instead of producing a compile warning, making web search usable even in repos without GitHub tooling (e.g. Azure DevOps-hosted). See Web Search reference. (#62957) - Dynamic
failure-issue-repofor reusable workflows βsafe-outputs.failure-issue-reponow accepts${{ inputs.* }}expressions, matching existing support forreport-failure-as-issueandreport-failed-jobs, so reusable (workflow_call) workflows can route failure issues per caller without patching the compiled lock file. (#62945) - Gateway steering events in audit output β
gh aw auditnow surfacestoken_steeringandtimeout_steeringevents (type, message, timestamp) asgateway_steering_eventsin both JSON and console output, making it easier to see when runs are approaching AI Credit or time limits. (#62943)
π Bug Fixes & Improvements
- Fixed cancelled AIC component accounting β cancelled compiler-owned component jobs are now only counted as zero AI Credits when GitHub job metadata proves execution never started; jobs with assigned runners, steps, or incomplete metadata are still accounted for correctly. (#62984)
- Safe-outputs checkout detection fixed for nested repos β the
find_repo_checkoutgit-scan fallback now trusts scanned repositories cloned via asteps:entry or manualactions/checkout, fixing a regression where the containerized safe-outputs MCP server (different UID) couldn't read nested checkouts due to git'ssafe.directorytrust not propagating beyondGITHUB_WORKSPACE. (#62944)
π Documentation
- Stale lock-file detection guidance β new docs explain how to detect stale/missing compiled
.lock.ymlfiles viagh aw list --jsonfor CI enforcement, plus remediation steps for contributors. (#62947) - Portable OTLP helper paths β OpenTelemetry/qmd examples now resolve the helper via
RUNNER_TEMPinstead of a hardcoded/tmp, for portability across runner environments. (#62940)
π§ Internal
- Updated GitHub Actions versions and refreshed parser/repoutil/semverutil/sliceutil spec extractions.
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
o205451.ingest.us.sentry.io
To allow these domains, add them to the network.allowed list in your workflow frontmatter:
network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"See Network Configuration for more information.
Generated by π Release Β· copilot Β· auto Β· 21.7 AIC Β· β 11.6K
What's Changed
- [spec-extractor] Update package specifications for parser, repoutil, semverutil, sliceutil by @github-actions[bot] in #62922
- [actions] Update GitHub Actions versions - 2026-09-23 by @github-actions[bot] in #62899
- Use portable path for OTLP helper guidance by @pelikhan with @Copilot in #62940
- [blog] Agent of the Day β 2026-09-23 by @github-actions[bot] in #62969
- Allow
${{ inputs.* }}expressions insafe-outputs.failure-issue-repofor reusable workflows by @pelikhan with @Copilot in #62945 - Document stale agentic workflow lock detection by @pelikhan with @Copilot in #62947
- Support native web-search on the Copilot engine by @pelikhan with @Copilot in #62957
- Fix cancelled daily AIC component accounting by @lpcox in #62984
- Report gateway steering events in audit output by @pelikhan with @Copilot in #62943
Full Changelog: v0.89.20...v0.89.21