Skip to content

Commit 55f52a8

Browse files
authored
Bump AWF to v0.27.44 and MCP Gateway to v0.4.8 (#50599)
1 parent fcd1855 commit 55f52a8

290 files changed

Lines changed: 6539 additions & 6293 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

.changeset/patch-bump-awf-v0-27-44-mcpg-v0-4-8.md

Lines changed: 5 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

.github/aw/actions-lock.json

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -170,26 +170,51 @@
170170
"digest": "sha256:04e2d1987a565000a8f114b89d806ae7a3864dd4f944be65275b28c93d8690e6",
171171
"pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.43@sha256:04e2d1987a565000a8f114b89d806ae7a3864dd4f944be65275b28c93d8690e6"
172172
},
173+
"ghcr.io/github/gh-aw-firewall/agent:0.27.44": {
174+
"image": "ghcr.io/github/gh-aw-firewall/agent:0.27.44",
175+
"digest": "sha256:0d727725c737b58c7bdf51f640cffb928385ec46517e0917c7f1a02f1bada8b4",
176+
"pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.27.44@sha256:0d727725c737b58c7bdf51f640cffb928385ec46517e0917c7f1a02f1bada8b4"
177+
},
173178
"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.43": {
174179
"image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.43",
175180
"digest": "sha256:d85f57975af5ea23af4996e41ed73fbc8f5b4a47402472bfe82e508f352cb0c1",
176181
"pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.43@sha256:d85f57975af5ea23af4996e41ed73fbc8f5b4a47402472bfe82e508f352cb0c1"
177182
},
183+
"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44": {
184+
"image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44",
185+
"digest": "sha256:b50fbadba138f6e9aba94aca09711335c489bb3b15861220cb66f6092e042dc7",
186+
"pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44@sha256:b50fbadba138f6e9aba94aca09711335c489bb3b15861220cb66f6092e042dc7"
187+
},
178188
"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.43": {
179189
"image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.43",
180190
"digest": "sha256:65c45ea2967984d0024f3df61bc71335658a77ede96c8d9665da7a5f33a795ab",
181191
"pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.43@sha256:65c45ea2967984d0024f3df61bc71335658a77ede96c8d9665da7a5f33a795ab"
182192
},
193+
"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44": {
194+
"image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44",
195+
"digest": "sha256:c064d15974f7c933ec7d3f7b4038f4fd203547b3154bdc821afd379144887eff",
196+
"pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44@sha256:c064d15974f7c933ec7d3f7b4038f4fd203547b3154bdc821afd379144887eff"
197+
},
183198
"ghcr.io/github/gh-aw-firewall/squid:0.27.43": {
184199
"image": "ghcr.io/github/gh-aw-firewall/squid:0.27.43",
185200
"digest": "sha256:26be5e0b8c8f4c41c8a59126b29bb5d80b07253597472ded2a16bdd75abcbf9d",
186201
"pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.43@sha256:26be5e0b8c8f4c41c8a59126b29bb5d80b07253597472ded2a16bdd75abcbf9d"
187202
},
203+
"ghcr.io/github/gh-aw-firewall/squid:0.27.44": {
204+
"image": "ghcr.io/github/gh-aw-firewall/squid:0.27.44",
205+
"digest": "sha256:83e48bbe12c634be8c228a576832fe45f66c529ac3659db92bddbcf2eeb6d627",
206+
"pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.27.44@sha256:83e48bbe12c634be8c228a576832fe45f66c529ac3659db92bddbcf2eeb6d627"
207+
},
188208
"ghcr.io/github/gh-aw-mcpg:v0.4.7": {
189209
"image": "ghcr.io/github/gh-aw-mcpg:v0.4.7",
190210
"digest": "sha256:7545220a9aca134b71e51193ee0eaf4c50756ebf8fbd25a63ae7556e62815c00",
191211
"pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.4.7@sha256:7545220a9aca134b71e51193ee0eaf4c50756ebf8fbd25a63ae7556e62815c00"
192212
},
213+
"ghcr.io/github/gh-aw-mcpg:v0.4.8": {
214+
"image": "ghcr.io/github/gh-aw-mcpg:v0.4.8",
215+
"digest": "sha256:38bbea36cdb46a3c9d04d1db05e672966f5239b431a2022eb35881688e5721d8",
216+
"pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.4.8@sha256:38bbea36cdb46a3c9d04d1db05e672966f5239b431a2022eb35881688e5721d8"
217+
},
193218
"ghcr.io/github/gh-aw-node": {
194219
"image": "ghcr.io/github/gh-aw-node",
195220
"digest": "sha256:0d9f1fb5fd6610c0ac1f5194a38e45a8a1e81f8a390d5142d8e4e6f26a4b3196",

.github/aw/create-agentic-workflow.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -354,7 +354,7 @@ Before finalizing any newly generated workflow, verify:
354354
For cross-repository workflows, first determine whether the question is **finite and bounded**:
355355

356356
- If the agent needs to answer a finite, pre-approved question about a private repository (e.g. "does this repo have open critical issues?", "what is the latest release version?"):
357-
- Use `tools.github.bounded-queries` with `private-repos` and `sandbox.agent.id: awf` (AWF v0.28.0+)
357+
- Use `tools.github.bounded-queries` with `private-repos` and `sandbox.agent.id: awf` (AWF v0.27.44+)
358358
- This is the preferred approach — no raw source code is exposed and no cross-repo token is needed
359359
- Select `runtime: sbx` only when experimental, capability-gated execution is intended. Each query gets a separate sbx VM; AWF fails closed during host preflight and never falls back to Docker or gVisor.
360360
- If the answer is unbounded (e.g. arbitrary source-code extraction, full file contents), or if bounded queries are not appropriate:

.github/aw/designer.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -213,7 +213,7 @@ For less common ecosystems (Swift, PHP, Dart, Haskell, Perl, fonts, Deno, Elixir
213213
| "run commands/tests" | `bash` tool (default unless restricted) |
214214
| "browse web pages/docs" | `web-fetch` and/or `web-search` |
215215
| "test UI flows" | `playwright` |
216-
| "finite question about private repo" | `tools.github.bounded-queries` (AWF v0.28.0+, preferred over cross-repo tokens) |
216+
| "finite question about private repo" | `tools.github.bounded-queries` (AWF v0.27.44+, preferred over cross-repo tokens) |
217217

218218
### Pattern Heuristics
219219

.github/aw/syntax-agentic.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -319,7 +319,7 @@ description: Agentic workflow specific frontmatter fields for GitHub Agentic Wor
319319
- **Strict mode**: `sandbox.agent` blocks without an explicit `id: awf` are rejected in strict mode. Any non-nil, non-disabled agent config without `id`/`type` defaults to AWF at runtime.
320320

321321
- **`tools:`** - Tool configuration for the coding agent (`github`, `agentic-workflows`, `edit`, `web-fetch`, `web-search`, `bash`, `playwright`, custom MCP server names, plus `timeout`/`startup-timeout`/`cli-proxy`). See [syntax-tools-imports.md](syntax-tools-imports.md#tool-configuration) for the full schema (GitHub `mode`/`toolsets`/integrity fields, bash allowlist decision rule, Playwright CLI mode).
322-
- **`tools.github.bounded-queries`** (object, AWF v0.28.0+) configures the AWF bounded-query subsystem for cross-repository private data access. When present, the agent may answer finite, pre-approved questions about the listed repositories using the generated `bounded-query` skill — without receiving raw source code. This is the preferred pattern for cross-repository workflows. Requires the AWF sandbox (`sandbox.agent.id: awf`). The query runtime is independent from `sandbox.agent.runtime`, and every query runs in a fresh backend-specific sandbox. All optional fields use AWF defaults when omitted.
322+
- **`tools.github.bounded-queries`** (object, AWF v0.27.44+) configures the AWF bounded-query subsystem for cross-repository private data access. When present, the agent may answer finite, pre-approved questions about the listed repositories using the generated `bounded-query` skill — without receiving raw source code. This is the preferred pattern for cross-repository workflows. Requires the AWF sandbox (`sandbox.agent.id: awf`). The query runtime is independent from `sandbox.agent.runtime`, and every query runs in a fresh backend-specific sandbox. All optional fields use AWF defaults when omitted.
323323

324324
```yaml
325325
tools:

0 commit comments

Comments
 (0)