Skip to content

v0.90.1

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 30 Sep 17:20
Immutable release. Only release title and notes can be modified.
856e7fa

🌟 Release Highlights

This release expands ledger support for repo-memory and deepens audit visibility into usage, threat detection, and experiments.

✨ What's New

  • Standalone safe-output-backed ledgers with replay projections, and default ledgers preserved when importing shared workflows (#64354, #64420, #64464)
  • Richer audit and usage artifacts: ledger transactions, threat-detection outcomes, experiment/evals data, and friction costs attributed to audit sources (#64509, #64506, #64339, #64338)
  • Narrowed add-labels schemas for triage workflows and required-labels gating for assign-to-agent (#64179, #64266, #64174)
  • Self-hosted runner enforcement at compile time (#64173)
  • Sandbox frontmatter fields normalized to kebab-case (#64302)

🐛 Bug Fixes & Improvements

  • Honor runtimes.node action override in threat-detection and evals Setup Node.js steps (#64498)
  • Handle malformed aw_context in manual dispatches (#64335)
  • Preserve version labels on SHA-pinned actions and resolvable safe-output targets (#64175, #64176)
  • Infer Copilot wire API for utility model variants (#64177)
  • version output now written to stdout (#64336)
  • Generated files filtered from reviewer PR diffs (#64357)
  • Hardened private-to-public flow validation (#64267)
  • Claude Code CLI updated to 2.1.280 and engine CLI pins refreshed (#64127, #64359)

📚 Documentation

  • Documented the SEC-005 exemption for ledger pushes and trimmed the measuring-impact guide (#64499, #64375)

Generated by 🚀 Release · copilot · auto · 13.3 AIC · ⊞ 11.5K


What's Changed

  • Fix upload-assets job summary formatting by @pelikhan with @Copilot in #64089
  • Add Daily Ecosystem Explorer agentic workflow by @pelikhan with @Copilot in #64096
  • Repoint pydantic-ai engine import from archived pydantic-ai-harness to pydantic/pydantic-ai by @pelikhan with @Copilot in #64093
  • Update generated Claude Code CLI to 2.1.280 by @lpcox with @Copilot in #64127
  • [docs] docs: unbloat MCP gateway changelog by @github-actions[bot] in #64145
  • Preserve resolvable safe-output targets by @pelikhan with @Copilot in #64176
  • Preserve version labels on SHA-pinned workflow actions by @pelikhan with @Copilot in #64175
  • [docs] Update glossary - daily scan by @github-actions[bot] in #64244
  • [spec-extractor] Update package specifications for stringutil, styles, testutil, timeutil by @github-actions[bot] in #64238
  • [eslint-miner] Add no-single-char-string-replace rule by @github-actions[bot] in #64232
  • [instructions] Sync instruction files with release v0.89.21 (follow-ups) by @github-actions[bot] in #64228
  • [actions] Update GitHub Actions versions - 2026-09-29 by @github-actions[bot] in #64213
  • Allow workflows to narrow add-labels item schemas by @pelikhan with @Copilot in #64179
  • Add required-labels gating to assign-to-agent by @pelikhan with @Copilot in #64174
  • Infer Copilot wire API for utility model variants by @pelikhan with @Copilot in #64177
  • Enable narrowed label schemas in triage workflows by @pelikhan with @Copilot in #64266
  • Enforce self-hosted runners during compilation by @pelikhan with @Copilot in #64173
  • Harden private-to-public flow validation by @pelikhan with @Copilot in #64267
  • [dead-code] chore: remove dead functions — 1 function removed by @github-actions[bot] in #64288
  • Normalize sandbox frontmatter fields to kebab-case by @pelikhan with @Copilot in #64302
  • [linter-miner] Add close-error-unchecked linter for resource cleanup error detection by @github-actions[bot] in #64310
  • [WIP] Add distributed ledger capability to repo-memory by @pelikhan with @Copilot in #64199
  • Move daily workflow review history to repo-memory ledgers by @pelikhan with @Copilot in #64337
  • Filter generated files before assembling reviewer PR diffs by @pelikhan with @Copilot in #64357
  • Attribute friction costs to audit sources by @pelikhan with @Copilot in #64338
  • Write version output to stdout by @pelikhan with @Copilot in #64336
  • Update agentic engine CLI pins and recompile workflows by @pelikhan with @Copilot in #64359
  • Collect experiment and evals data in the usage artifact for audit by @pelikhan with @Copilot in #64339
  • [docs] Self-healing documentation fixes from issue analysis - 2026-09-29 by @github-actions[bot] in #64367
  • [docs] docs: unbloat measuring impact by @github-actions[bot] in #64375
  • Handle malformed aw_context in manual dispatches by @pelikhan with @Copilot in #64335
  • Use GitHub App token for gh-proxy by @pelikhan with @Copilot in #64334
  • Add standalone safe-output-backed ledger configuration by @pelikhan with @Copilot in #64354
  • Add replay projections to standalone ledgers by @pelikhan with @Copilot in #64420
  • Allow arXiv researcher to update its ledger and dedup cache by @pelikhan with @Copilot in #64473
  • Preserve default ledgers when importing shared workflows by @pelikhan with @Copilot in #64464
  • Document SEC-005 exemption for ledger pushes by @pelikhan with @Copilot in #64499
  • Recognize consequence-based empty-catch rationale by @pelikhan with @Copilot in #64501
  • Remove dynamic eval from update-release tests by @pelikhan with @Copilot in #64502
  • Update stale CLI and scanner image pins by @pelikhan with @Copilot in #64500
  • Surface ledger transactions in conclusion usage and audit results by @pelikhan with @Copilot in #64509
  • Honor runtimes.node action override in threat-detection and evals Setup Node.js steps by @pelikhan with @Copilot in #64498
  • Surface threat-detection outcomes in usage artifacts and audit reports by @pelikhan with @Copilot in #64506

Full Changelog: v0.90.0...v0.90.1