Skip to content

bump: gh-aw-firewall v0.25.6, gh-aw-mcpg v0.2.11#23879

Merged
pelikhan merged 2 commits intomainfrom
copilot/update-gh-aw-firewall-mcpg
Apr 1, 2026
Merged

bump: gh-aw-firewall v0.25.6, gh-aw-mcpg v0.2.11#23879
pelikhan merged 2 commits intomainfrom
copilot/update-gh-aw-firewall-mcpg

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented Apr 1, 2026

Updates default versions for the two core runtime dependencies and regenerates all compiled workflow lock files.

Changes

  • pkg/constants/constants.go
    • DefaultFirewallVersion: v0.25.5v0.25.6
    • DefaultMCPGatewayVersion: v0.2.10v0.2.11
  • gh-aw.wasm — rebuilt against updated constants
  • 179 .lock.yml files — recompiled to pick up new versions


✨ PR Review Safe Output Test - Run 23847925954

💥 [THE END] — Illustrated by Smoke Claude ·

@pelikhan pelikhan marked this pull request as ready for review April 1, 2026 12:11
Copilot AI review requested due to automatic review settings April 1, 2026 12:11
@pelikhan pelikhan added the smoke label Apr 1, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Apr 1, 2026

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Apr 1, 2026

✅ All tools validated successfully! Agent Container Smoke Test confirms agent container is ready.

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Apr 1, 2026

🎬 THE ENDSmoke Claude MISSION: ACCOMPLISHED! The hero saves the day! ✨

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Apr 1, 2026

📰 BREAKING: Smoke Copilot is now investigating this pull request. Sources say the story is developing...

@github-actions github-actions bot removed the smoke label Apr 1, 2026
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR bumps the repository’s default runtime dependency versions for gh-aw-firewall (AWF) and gh-aw-mcpg (MCP Gateway), and updates generated workflow lockfiles to reflect the new versions.

Changes:

  • Update DefaultFirewallVersion to v0.25.6 and DefaultMCPGatewayVersion to v0.2.11.
  • Regenerate compiled workflow lock files to pin AWF image tags (0.25.6) and MCP Gateway image tags (v0.2.11) consistently.

Reviewed changes

Copilot reviewed 85 out of 180 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
pkg/constants/constants.go Bumps default AWF and MCP Gateway versions used across workflow compilation.
.github/workflows/workflow-generator.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/test-workflow.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/test-dispatcher.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/smoke-gemini.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/repo-tree-map.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/refiner.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/pr-triage-agent.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/poem-bot.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/plan.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/notion-issue-summary.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/metrics-collector.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/jsweep.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/issue-triage-agent.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/issue-monster.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/gpclean.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/github-remote-mcp-auth-test.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/firewall.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/example-permissions-warning.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/dev.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/dependabot-burner.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/daily-team-status.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/daily-malicious-code-scan.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/craft.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/contribution-check.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/constraint-solving-potd.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/codex-github-remote-mcp-test.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/code-simplifier.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/changeset.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/bot-detection.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/ai-moderator.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
.github/workflows/ace-editor.lock.yml Updates pinned AWF/MCPG versions in generated workflow steps and pre-pulled images.
… plus additional compiled .lock.yml workflow files (not included in the excerpt) Bulk regeneration to keep pinned versions consistent across workflows.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines 371 to +372
// DefaultFirewallVersion is the default version of the gh-aw-firewall (AWF) binary
const DefaultFirewallVersion Version = "v0.25.5"
const DefaultFirewallVersion Version = "v0.25.6"
Copy link

Copilot AI Apr 1, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PR description mentions that gh-aw.wasm was rebuilt/updated, but there is no gh-aw.wasm artifact present in the repository state for this PR (it does not appear in the repo root or under docs assets). Either include the updated wasm artifact in the PR (if it is meant to be version-pinned/committed) or adjust the PR description to avoid implying a tracked binary was regenerated.

Copilot uses AI. Check for mistakes.
@github-actions github-actions bot mentioned this pull request Apr 1, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Apr 1, 2026

Agent Container Tool Check

Tool Status Version
bash 5.2.21
sh available
git 2.53.0
jq 1.7
yq v4.52.4
curl 8.5.0
gh 2.88.1
node v20.20.1
python3 3.12.3
go 1.24.13
java 21.0.10 (Temurin)
dotnet 10.0.201

Result: 12/12 tools available ✅ PASS

🔧 Tool validation by Agent Container Smoke Test ·

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Apr 1, 2026

🤖 Smoke test complete for run 23847925985

Test Result
GitHub MCP
MCP Scripts GH CLI
Serena MCP
Playwright
Web Fetch
File Writing + Bash
Discussion Interaction
Build gh-aw
Discussion Creation
Workflow Dispatch
PR Review

Overall: ⚠️ PARTIAL PASS (Playwright: permission denied on log dir)

PR Author: @Copilot | Assignees: @pelikhan, @Copilot

📰 BREAKING: Report filed by Smoke Copilot ·

Copy link
Copy Markdown
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Routine version bump PR updating gh-aw-firewall to v0.25.6 and gh-aw-mcpg to v0.2.11. All 179 lock files recompiled. Changes look consistent and correct.

📰 BREAKING: Report filed by Smoke Copilot

GH_AW_INFO_ALLOWED_DOMAINS: '["defaults"]'
GH_AW_INFO_FIREWALL_ENABLED: "true"
GH_AW_INFO_AWF_VERSION: "v0.25.5"
GH_AW_INFO_AWF_VERSION: "v0.25.6"
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Version bump to v0.25.6 looks correct — matches the DefaultFirewallVersion constant update in pkg/constants/constants.go.

await determineAutomaticLockdown(github, context, core);
- name: Download container images
run: bash ${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh ghcr.io/github/gh-aw-firewall/agent:0.25.5 ghcr.io/github/gh-aw-firewall/api-proxy:0.25.5 ghcr.io/github/gh-aw-firewall/squid:0.25.5 ghcr.io/github/gh-aw-mcpg:v0.2.10 ghcr.io/github/github-mcp-server:v0.32.0
run: bash ${RUNNER_TEMP}/gh-aw/actions/download_docker_images.sh ghcr.io/github/gh-aw-firewall/agent:0.25.6 ghcr.io/github/gh-aw-firewall/api-proxy:0.25.6 ghcr.io/github/gh-aw-firewall/squid:0.25.6 ghcr.io/github/gh-aw-mcpg:v0.2.11 ghcr.io/github/github-mcp-server:v0.32.0
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MCP Gateway version bump to v0.2.11 — confirmed consistent across download_docker_images.sh call and GH_AW_INFO_AWMG_VERSION in lock files. 👍

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Apr 1, 2026

📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Apr 1, 2026


Warning

The push_to_pull_request_branch operation failed: Cannot push to pull request branch: patch modifies files outside the allowed-files list (smoke-test-pr-push-23847925954.smoke). Add the files to the allowed-files configuration field or remove them from the patch.. The code changes were not applied.

Smoke Test 23847925954§run

Core: 1✅ 2✅ 3✅ 4✅ 5✅ 6✅ 7✅ 8✅ 9✅ 10✅ 11✅
PR Review: 12✅ 13✅ 14✅ 15⚠️ 16✅ 17✅ 18⚠️

Overall: PARTIAL (2 skipped, 0 failed)

💥 [THE END] — Illustrated by Smoke Claude ·

Copy link
Copy Markdown
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💥 Automated smoke test review - all systems nominal!

💥 [THE END] — Illustrated by Smoke Claude

@@ -369,7 +369,7 @@ const DefaultGitHubMCPServerVersion Version = "v0.32.0"
const DefaultGitHubLockdown = false

// DefaultFirewallVersion is the default version of the gh-aw-firewall (AWF) binary
const DefaultFirewallVersion Version = "v0.25.5"
const DefaultFirewallVersion Version = "v0.25.6"
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Smoke test review comment #1: This file contains version constants. The bump to v0.25.6 looks correct and consistent with the PR description.

@@ -369,7 +369,7 @@ const DefaultGitHubMCPServerVersion Version = "v0.32.0"
const DefaultGitHubLockdown = false

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Smoke test review comment #2: Version constants look well-organized. Consider adding a comment explaining the versioning scheme for future maintainers.

@pelikhan pelikhan merged commit bf5893a into main Apr 1, 2026
204 of 207 checks passed
@pelikhan pelikhan deleted the copilot/update-gh-aw-firewall-mcpg branch April 1, 2026 12:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants