Repository navigation
v0.91.2
Pre-release
Pre-release
·
73 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
🌟 Release Highlights
This release deepens observability with richer unified agent sessions, and hardens security around secret masking, post-steps, and package scanning.
✨ What's New
- Richer unified agent sessions: sessions now include split prompts, GitHub API rate limits, and daily AIC decisions, with estimated credits clearly distinguished from recorded usage.
- Dynamic workflow smoke coverage: new smoke tests for dynamic workflows (including Claude) and opt-in engine defaults.
- Wildcard GitHub App repositories are now allowed explicitly in strict mode.
🐛 Bug Fixes & Improvements
- Security: post-steps can no longer create issues directly or access safe-outputs; package resource scanning is file-aware; artifact redaction covers regex-shaped MCP gateway masks; non-writable files are prepared for custom secret masking.
- Engines: Pi codemode compatibility and reasoning configuration fixed; Codex code-mode exec disabled for GitHub inference; pinned Node.js versions honored in detection and evals jobs.
- Reliability: transient issue-listing failures are retried when publishing essential issues; Copilot session summary fallbacks fixed.
- Reporting: engine conversation reports are cleaner with collapsed streamed messages; structured data in safe-output issues is collapsed.
- MCP gateway updated to v0.4.29.
Generated by 🚀 Release · copilot · auto · 15.1 AIC · ⊞ 11.6K
What's Changed
- [docs] docs: unbloat sharing-workflows.md by @github-actions[bot] in #65973
- Fix Copilot session summary source fallbacks by @pelikhan in #65979
- Bump source-map-js from 1.2.1 to 1.2.2 in /eslint-factory in the npm_and_yarn group across 1 directory by @dependabot[bot] in #65980
- Bump the npm_and_yarn group across 1 directory with 4 updates by @dependabot[bot] in #65983
- Bump the npm_and_yarn group across 1 directory with 2 updates by @dependabot[bot] in #65981
- [community] Update community contributions in README by @github-actions[bot] in #65994
- Include split prompts in the unified agent session by @pelikhan with @Copilot in #66011
- fix: collapse structured data in safe-output issues by @pelikhan in #66025
- Make package resource security scanning file-aware by @pelikhan with @Copilot in #65961
- Honor pinned Node.js versions in detection and evals jobs by @pelikhan with @Copilot in #66040
- Cover regex-shaped MCP gateway masks in artifact redaction by @pelikhan with @Copilot in #66041
- Include GitHub API rate limits in unified agent sessions by @pelikhan with @Copilot in #66047
- [spec-enforcer] Enforce specifications for ctxutil, envutil, errorutil by @github-actions[bot] in #66106
- Fix engine conversation reports and collapse streamed messages by @pelikhan in #66048
- Distinguish estimated credits from recorded daily AIC usage by @pelikhan with @Copilot in #66043
- Allow explicit wildcard GitHub App repositories in strict mode by @pelikhan with @Copilot in #66039
- [WIP] Fix compiled lock files and zizmor pedantic audit issues by @pelikhan with @Copilot in #66042
- [spec-extractor] Update package specifications for agentdrain, cli, console, constants by @github-actions[bot] in #66085
- Bump golang.org/x/tools from 0.50.0 to 0.51.0 by @dependabot[bot] in #66087
- Bump prettier from 3.9.8 to 3.9.9 in /actions/setup/js by @dependabot[bot] in #66088
- Retry transient issue-listing failures in essential issue publishing by @pelikhan with @Copilot in #66123
- Refresh workflow pins and bundle Dependabot updates by @pelikhan with @Copilot in #66124
- [ci-coach] Fix failing pkg/workflow unit tests (stale goldens and expectations) by @github-actions[bot] in #66180
- Record daily AIC decisions in unified sessions by @pelikhan with @Copilot in #66126
- Bump starlight-github-alerts from 0.4.0 to 0.5.0 in /docs by @dependabot[bot] in #66093
- Bump mermaid from 12.0.0 to 12.1.0 in /docs by @dependabot[bot] in #66091
- Bump @astrojs/starlight from 0.42.4 to 0.42.5 in /docs by @dependabot[bot] in #66090
- Disable Codex code-mode exec for GitHub inference by @pelikhan in #66179
- fix: prepare non-writable files for custom secret masking by @pelikhan in #66160
- Reject direct issue creation and safe-output access in post-steps by @pelikhan with @Copilot in #66064
- [fp-enhancer] Improve pkg/actionpins cache immutability by @github-actions[bot] in #66086
- Fix Pi codemode compatibility and reflected reasoning configuration by @pelikhan in #66209
- Add Claude dynamic workflow smoke coverage and unified task events by @pelikhan in #66208
- Add dynamic workflow smoke and opt-in engine defaults by @pelikhan in #66195
Full Changelog: v0.91.1...v0.91.2