diff --git a/.github/workflows/classify-pull-request-risk.lock.yml b/.github/workflows/classify-pull-request-risk.lock.yml index 71bc70f6..21b15ad4 100644 --- a/.github/workflows/classify-pull-request-risk.lock.yml +++ b/.github/workflows/classify-pull-request-risk.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"3aa65d0ac4fff87d2dabef52985cadae9af1411946715bf283e17408ec1fe806","body_hash":"9a642175e95595da533dc9f330d89ecde2be8e186a4390562539083cbd20efaa","compiler_version":"v0.83.4","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.75"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"282b8a5858bfa9588b3ad80d3afd60958b5cab140d10dd5fcd009d772102e928","body_hash":"9a642175e95595da533dc9f330d89ecde2be8e186a4390562539083cbd20efaa","compiler_version":"v0.83.4","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.75"}} # gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"e89c65e17eb281bbd5ff2ff9e9199a03e96654c7","version":"v0.83.4"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.42","digest":"sha256:26a8af4e5566485b02f52af59ee03803ae798271a9619d4767e94d07806deb9b","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.42@sha256:26a8af4e5566485b02f52af59ee03803ae798271a9619d4767e94d07806deb9b"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.42","digest":"sha256:944f2686c9ab9bec338fd14b662461662f77cd12cd0ea8a3e7cb8c0987cd1607","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.42@sha256:944f2686c9ab9bec338fd14b662461662f77cd12cd0ea8a3e7cb8c0987cd1607"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.42","digest":"sha256:da006bf96d2d246dd269d57b233c1798d2ad63d6cd64ca02f7bf71045028781f","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.42@sha256:da006bf96d2d246dd269d57b233c1798d2ad63d6cd64ca02f7bf71045028781f"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.42","digest":"sha256:42dfeb649c680a8558cd5423dbc530b653a69413e35ffbe5e71da5d48c94bdf0","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.42@sha256:42dfeb649c680a8558cd5423dbc530b653a69413e35ffbe5e71da5d48c94bdf0"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.6","digest":"sha256:fecabec51bbc41f2ad61076d6bcd9a36ef23b142e672a444e054d37fc29de93c","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.6@sha256:fecabec51bbc41f2ad61076d6bcd9a36ef23b142e672a444e054d37fc29de93c"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.7.0","digest":"sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308","pinned_image":"ghcr.io/github/github-mcp-server:v1.7.0@sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308"}]} # This file was automatically generated by gh-aw (v0.83.4). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # @@ -277,20 +277,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_c3bcb2a4b30a6586_EOF' + cat << 'GH_AW_PROMPT_2e67eb9a6f807244_EOF' - GH_AW_PROMPT_c3bcb2a4b30a6586_EOF + GH_AW_PROMPT_2e67eb9a6f807244_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_c3bcb2a4b30a6586_EOF' + cat << 'GH_AW_PROMPT_2e67eb9a6f807244_EOF' Tools: add_labels, remove_labels(max:5), missing_tool, missing_data, noop - GH_AW_PROMPT_c3bcb2a4b30a6586_EOF + GH_AW_PROMPT_2e67eb9a6f807244_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_c3bcb2a4b30a6586_EOF' + cat << 'GH_AW_PROMPT_2e67eb9a6f807244_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -319,26 +319,26 @@ jobs: {{/if}} - GH_AW_PROMPT_c3bcb2a4b30a6586_EOF + GH_AW_PROMPT_2e67eb9a6f807244_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/cli_proxy_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_c3bcb2a4b30a6586_EOF' + cat << 'GH_AW_PROMPT_2e67eb9a6f807244_EOF' # Agent Framework Pull Request Risk Classifier - + Classify pull request `__GH_AW_INPUTS_PR_NUMBER__` in `__GH_AW_GITHUB_REPOSITORY__` only when the evidence supports one risk level with high confidence. - + The deterministic classifier already handled unambiguous low-risk changes. This agent reviews every production or otherwise ambiguous change. A wrong risk label is worse than abstaining. Before this agent starts, the deterministic stage adds `pending-auto-risk` and clears every existing risk label. A confident classification must therefore actively add one risk label and remove the pending marker. - + ## Risk Levels - + - `risk:low`: Limited blast radius and straightforward rollback. Examples include documentation, comments, examples, tests that do not alter production behavior, isolated internal fixes, and patch dependency updates with no meaningful runtime impact. - `risk:medium`: Contained production impact with a reasonable rollback. Examples include backwards-compatible API additions, bounded feature or bug-fix behavior, minor dependency upgrades, retries, timeouts, streaming, tool invocation, error handling, or refactoring across several packages. - `risk:high`: Large blast radius, difficult rollback, security implications, or compatibility risk. Examples include authentication, authorization, secrets, tool permissions or code execution, breaking APIs, core orchestration, checkpointing, persistence, serialization compatibility, significant concurrency changes, major dependency upgrades, or inadequate tests for the possible impact. - + ## Signals - + Use all available evidence rather than treating any single label as decisive: - + - Assess the regression risk introduced by this proposed change, not merely how sensitive the touched component is. A small, well-tested safeguard or bounded bug fix in a sensitive area is usually `risk:medium`, not automatically `risk:high`. - `size:*` indicates review surface, not semantic risk by itself. - `kind:*` distinguishes code, tests, documentation, examples, dependencies, and CI. @@ -347,37 +347,37 @@ jobs: - For dependency changes, inspect whether the update is patch, minor, or major and whether it changes runtime behavior. - `public-api-change` is positive evidence that exported API changed, but it does not prove the change is breaking. Its absence is not proof that no API changed because the parity workflow may still be running. - Review the actual diff and test changes to distinguish an isolated fix from a broad behavioral change. - + ## Confidence Gates - + Apply a risk label only when the actual diff provides concrete evidence for that level: - + - Use `risk:low` only when there is no meaningful production behavior change, or the change is obviously isolated, directly tested, and straightforward to roll back. - Use `risk:medium` only when production impact is clearly bounded, compatibility is preserved, tests cover the changed behavior, and no high-risk criterion is present. - Use `risk:high` only when the diff itself shows a concrete high-risk property such as a breaking API, weakened trust boundary, persistence or serialization incompatibility, broad orchestration or concurrency impact, major dependency upgrade, difficult rollback, or inadequate tests for the potential impact. A sensitive path alone is not sufficient. - + Abstain by adding `failed-auto-risk` when any of these are true: - + - Required files, patches, labels, or dependency-version details cannot be read. - Classification depends on assumptions not established by the diff. - More than one risk level remains reasonably plausible. - The test evidence or rollback scope is unclear. - You cannot cite concrete evidence for the selected level. - + Do not guess, choose a default, or round uncertainty up to a higher risk level. - + ## Process - + 1. Use GitHub tools to read the PR title, body, existing labels, changed files, and relevant diff patches. Do not execute pull request code. 2. Apply the confidence gates above. Select exactly one risk level only when one level is clearly supported; otherwise abstain. 3. On success, add the selected risk label, remove the other two risk labels, and remove `pending-auto-risk` and `failed-auto-risk` if present. Do not remove labels outside this allowlist. The safe-output target is already fixed to this PR, so omit `item_number` from label calls. If the tool requires it, pass the bare integer `__GH_AW_INPUTS_PR_NUMBER__`; never pass a string or prefix it with `#`. 4. If the selected risk label is already the only risk label and neither marker is present, use `noop`. 5. Do not add comments or reviews. 6. If the PR cannot be read or classified confidently, add `failed-auto-risk`, remove `pending-auto-risk`, and do not add a risk label. - + The workflow validates the final state after this agent finishes. A valid automatic result is either exactly one risk label with no marker, or `failed-auto-risk` with no risk or pending label. Missing, pending, conflicting, or mixed states are converted to the unable marker and fail the workflow check. - GH_AW_PROMPT_c3bcb2a4b30a6586_EOF + GH_AW_PROMPT_2e67eb9a6f807244_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -481,7 +481,6 @@ jobs: aic: ${{ steps.parse-mcp-gateway.outputs.aic }} ambient_context: ${{ steps.parse-mcp-gateway.outputs.ambient_context }} artifact_prefix: ${{ needs.activation.outputs.artifact_prefix }} - checkout_pr_success: ${{ steps.checkout-pr.outputs.checkout_pr_success || 'true' }} effective_tokens: ${{ steps.parse-mcp-gateway.outputs.effective_tokens }} has_patch: ${{ steps.collect_output.outputs.has_patch }} http_400_response_error: ${{ steps.detect-agent-errors.outputs.http_400_response_error || 'false' }} @@ -520,10 +519,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise @@ -535,26 +530,6 @@ jobs: with: name: ${{ needs.activation.outputs.artifact_prefix }}activation path: /tmp/gh-aw - - name: Configure Git credentials - env: - GITHUB_REPOSITORY: ${{ github.repository }} - GITHUB_SERVER_URL: ${{ github.server_url }} - GITHUB_TOKEN: ${{ github.token }} - run: bash "${RUNNER_TEMP}/gh-aw/actions/configure_git_credentials.sh" - - name: Checkout PR branch - id: checkout-pr - if: | - github.event.pull_request || github.event.issue.pull_request || github.event_name == 'workflow_dispatch' && fromJSON(github.event.inputs.aw_context || '{}').item_type == 'pull_request' - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 - env: - GH_TOKEN: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} - with: - github-token: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} - script: | - const { setupGlobals } = require('${{ runner.temp }}/gh-aw/actions/setup_globals.cjs'); - setupGlobals(core, github, context, exec, io, getOctokit); - const { main } = require('${{ runner.temp }}/gh-aw/actions/checkout_pr_branch.cjs'); - await main(); - name: Install GitHub Copilot CLI run: bash "${RUNNER_TEMP}/gh-aw/actions/install_copilot_cli.sh" 1.0.75 env: @@ -579,12 +554,6 @@ jobs: GH_AW_TRUSTED_USERS_VAR: ${{ vars.GH_AW_GITHUB_TRUSTED_USERS || '' }} GH_AW_APPROVAL_LABELS_VAR: ${{ vars.GH_AW_GITHUB_APPROVAL_LABELS || '' }} run: bash "${RUNNER_TEMP}/gh-aw/actions/parse_guard_list.sh" - - name: Restore agent config folders from base branch - if: steps.checkout-pr.outcome == 'success' - env: - GH_AW_AGENT_FOLDERS: ".agents .antigravity .claude .codex .gemini .github .opencode .pi" - GH_AW_AGENT_FILES: "AGENTS.md ANTIGRAVITY.md CLAUDE.md GEMINI.md PI.md opencode.jsonc" - run: bash "${RUNNER_TEMP}/gh-aw/actions/restore_base_github_folders.sh" - name: Restore inline sub-agents from activation artifact env: GH_AW_SUB_AGENT_DIR: ".github/agents" @@ -927,12 +896,6 @@ jobs: id: detect-agent-errors continue-on-error: true run: node "${RUNNER_TEMP}/gh-aw/actions/detect_agent_errors.cjs" - - name: Configure Git credentials - env: - GITHUB_REPOSITORY: ${{ github.repository }} - GITHUB_SERVER_URL: ${{ github.server_url }} - GITHUB_TOKEN: ${{ github.token }} - run: bash "${RUNNER_TEMP}/gh-aw/actions/configure_git_credentials.sh" - name: Copy Copilot session state files to logs if: always() continue-on-error: true @@ -1302,7 +1265,6 @@ jobs: GH_AW_WORKFLOW_ID: "classify-pull-request-risk" GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURS: "168" GH_AW_ENGINE_ID: "copilot" - GH_AW_CHECKOUT_PR_SUCCESS: ${{ needs.agent.outputs.checkout_pr_success }} GH_AW_EFFECTIVE_TOKENS: ${{ needs.agent.outputs.effective_tokens || '' }} GH_AW_AI_CREDITS_RATE_LIMIT_ERROR: ${{ needs.agent.outputs.ai_credits_rate_limit_error || 'false' }} GH_AW_UNKNOWN_MODEL_AI_CREDITS: ${{ needs.agent.outputs.unknown_model_ai_credits || 'false' }} diff --git a/.github/workflows/classify-pull-request-risk.md b/.github/workflows/classify-pull-request-risk.md index 0972d5d2..88f88668 100644 --- a/.github/workflows/classify-pull-request-risk.md +++ b/.github/workflows/classify-pull-request-risk.md @@ -18,6 +18,7 @@ on: concurrency: group: "gh-aw-${{ github.workflow }}-${{ github.repository }}-${{ inputs.pr_number }}" cancel-in-progress: true +checkout: false permissions: contents: read issues: read