diff --git a/.github/workflows/gh-aw-code-quality-audit.lock.yml b/.github/workflows/gh-aw-code-quality-audit.lock.yml index d0243596..507aa0eb 100644 --- a/.github/workflows/gh-aw-code-quality-audit.lock.yml +++ b/.github/workflows/gh-aw-code-quality-audit.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"2d09e575832d111856c3b28f2d0d6037f67cbd8b33500b70a7674f0da4bdb25c","body_hash":"4dbd1861beff45ffcfeed9f1a50ad82e0c427efe9753e7046a057b2ae3c04e70","compiler_version":"v0.87.4","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.80"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"b1c2602fc0ca12306cd0cef25d31bff184f2b26981c9b765fb5ba4dc47711fb5","body_hash":"81279fe0f1f2cc16a8fc0612a418236f9d9a90a589bd91224573a6945d19c292","compiler_version":"v0.87.4","agent_id":"copilot","agent_model":"${{ inputs.model }}","engine_versions":{"copilot":"1.0.80"}} # gh-aw-manifest: {"version":1,"secrets":["GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"373c709c69115d41ff229c7e5df9f8788daa9553","version":"v9"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-go","sha":"40f1582b2485089dde7abd97c1529aa768e1baff","version":"v5"},{"repo":"actions/setup-node","sha":"6044e13b5dc448c55e2357c09f80417699197238","version":"v6"},{"repo":"actions/setup-python","sha":"a26af69be951a213d495a4c3e4e4022e16d87065","version":"v5"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"astral-sh/setup-uv","sha":"e58605a9b6da7c637471fab8847a5e5a6b8df081","version":"v5"},{"repo":"github/gh-aw-actions/setup-cli","sha":"ea4b911d44a5336c74325a122a5fd9110b45ff06","version":"v0.87.4"},{"repo":"github/gh-aw/actions/setup","sha":"83d6315352f7db8882090ff2026087842f4256b9","version":"v0.87.4"},{"repo":"ruby/setup-ruby","sha":"95ef2b042f9d7a56d8268cba8559e2842e2ad01b","version":"v1.321.0 (source v1)"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.28.4","digest":"sha256:8f18587981eff7e6291784200a88a7191d23bfd8f5723db848c640d6b4e88e46","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.28.4@sha256:8f18587981eff7e6291784200a88a7191d23bfd8f5723db848c640d6b4e88e46"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.4","digest":"sha256:64e668297d1b9d83ee102626e104c054ac2cf5cfd7225bf6e144f86962229882","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.4@sha256:64e668297d1b9d83ee102626e104c054ac2cf5cfd7225bf6e144f86962229882"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.28.4","digest":"sha256:35953d0beac18f642aa0bc98bb726a85288539b1fc630c16e94da33300058258","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.28.4@sha256:35953d0beac18f642aa0bc98bb726a85288539b1fc630c16e94da33300058258"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.10","digest":"sha256:08bb5fa417aed94b40a14e2b7b3ae457531a5f22b143a32fe58317139d9b8f42","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.10@sha256:08bb5fa417aed94b40a14e2b7b3ae457531a5f22b143a32fe58317139d9b8f42"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:0d9f1fb5fd6610c0ac1f5194a38e45a8a1e81f8a390d5142d8e4e6f26a4b3196","pinned_image":"ghcr.io/github/gh-aw-node@sha256:0d9f1fb5fd6610c0ac1f5194a38e45a8a1e81f8a390d5142d8e4e6f26a4b3196"},{"image":"ghcr.io/github/github-mcp-server:v1.10.0","digest":"sha256:097512ddf58af80a620c177ae9cad93448f9a2a55c70ee8fde5cec6714522a8c","pinned_image":"ghcr.io/github/github-mcp-server:v1.10.0@sha256:097512ddf58af80a620c177ae9cad93448f9a2a55c70ee8fde5cec6714522a8c"}],"mcp_servers":[{"name":"github","tools":["actions_get","actions_list","get_commit","get_file_contents","get_job_logs","get_label","get_latest_release","get_pull_request","get_pull_request_comments","get_pull_request_diff","get_pull_request_files","get_pull_request_review_comments","get_pull_request_reviews","get_pull_request_status","get_release_by_tag","get_tag","issue_read","list_branches","list_commits","list_issue_types","list_issues","list_label","list_pull_requests","list_releases","list_starred_repositories","list_tags","pull_request_read","search_code","search_issues","search_pull_requests","search_repositories"]},{"name":"public-code-search","tools":["search_code"]},{"name":"safeoutputs","tools":["create_issue","missing_data","missing_tool","noop"]}]} # This file was automatically generated by gh-aw (v0.87.4). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # @@ -115,6 +115,11 @@ on: description: Minimum severity to include in the report. 'high' = only report issues with clear user impact or correctness problems. 'medium' (default) = also include issues that degrade quality or maintainability. 'low' = also include minor deviations from best practices. required: false type: string + target-repo: + default: ${{ github.repository }} + description: Repository where audit issues are created, in owner/repo format. Defaults to the workflow repository; use GH_AW_GITHUB_TOKEN for cross-repository access. + required: false + type: string title-prefix: description: Title prefix for created issues (e.g. '[react-accessibility]') required: true @@ -321,6 +326,7 @@ jobs: GH_AW_EXPR_1A3A194A: ${{ github.event.discussion.number || (fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_type == 'discussion' && fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_number) }} GH_AW_EXPR_463A214A: ${{ github.event.pull_request.number || (fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_type == 'pull_request' && fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_number) }} GH_AW_EXPR_49B959F1: ${{ inputs.additional-instructions }} + GH_AW_EXPR_596E2A60: ${{ inputs.target-repo }} GH_AW_EXPR_802A9F6A: ${{ github.event.issue.number || (fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_type == 'issue' && fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_number) }} GH_AW_EXPR_BF503D80: ${{ inputs.title-prefix }} GH_AW_EXPR_FF1D34CE: ${{ github.event.comment.id || fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').comment_id }} @@ -347,7 +353,7 @@ jobs: GH_AW_PROMPT_CONTENT_0015: "You run on a schedule to investigate the repository and file an issue when something needs attention. Your specific assignment is described in the **Report Assignment** section below.\n\n## Constraints\n\nThis workflow is for detection and reporting only. You can read files, search code, run commands, and read PR/issue details — but your only output is either a single issue or a noop.\n\n## Process\n\nFollow these steps in order.\n\n### Step 1: Gather Context\n\n1. Read `/tmp/agents.md` for the repository's coding guidelines and conventions (skip if missing).\n2. Follow the data gathering instructions in the **Report Assignment** section.\n\n### Step 2: Analyze\n\nFollow the analysis instructions in the **Report Assignment** section to determine whether an issue should be filed. The Report Assignment defines:\n- What data to gather and how\n- What to look for\n- What constitutes a finding worth reporting\n- What to skip or ignore\n\n### Step 3: Self-Review (Quality Gate)\n\nBefore filing anything, critically evaluate every finding against these criteria:\n\n1. **Evidence is concrete** — you can point to exact file paths, line numbers, commit SHAs, or command outputs. No \"I believe\" or \"it seems.\"\n2. **Finding is actionable** — a maintainer reading the issue can act on it without re-investigating from scratch.\n3. **Finding is not already tracked** — you checked open issues and recent PRs for duplicates.\n4. **Finding is worth a human's time** — the issue is material enough that a maintainer would thank you for filing it, not close it as noise.\n\nIf zero findings pass all four criteria, call `noop` with a brief reason and stop. **Noop is the expected outcome most days.** Filing nothing is a success when there is nothing worth filing.\n\n### Step 4: Report\n\nIf there are findings that pass the quality gate, call `create_issue` with a structured report. Use the issue format specified in the Report Assignment if one is provided, otherwise use this default format:\n\n**Issue title:** Brief summary of findings\n\n**Issue body:**\n\n> ## Findings\n>\n> ### 1. [Brief description]\n>\n> **Evidence:** [Links, references, or data supporting the finding]\n> **Action needed:** [What should be done]\n>\n> ## Suggested Actions\n>\n> - [ ] [Actionable checkbox for each finding]\n\n**Guidelines:**\n- Group related findings together\n- Be specific about what needs to happen\n- Include links and references where possible\n- Make suggested actions concrete enough to act on without re-investigating\n- If a finding is ambiguous, it does not pass the quality gate — drop it\n\n**Report Assignment:**\n\n" GH_AW_PROMPT_CONTENT_0016: "\n" GH_AW_PROMPT_CONTENT_0017: "Analyze the codebase for quality issues and file a structured report when concrete, actionable findings exist.\n\n**The bar is high: only report issues backed by specific code evidence.** Most runs should end with `noop` — that means the code is in good shape for the dimension being audited. Filing nothing is a success when there is nothing worth filing.\n\n### Severity Threshold: `__GH_AW_EXPR_08E89BCD__`\n\nOnly include findings at or above the configured severity. Severity labels and meanings are defined by the importing workflow; this fragment uses the importing workflow's `__GH_AW_EXPR_08E89BCD__` semantics.\n\n### Evidence Standard\n\nEvery finding must include **all** of the following. Findings missing any element must be dropped:\n\n1. **Location** — File path(s) and precise location context (line numbers when available or another unambiguous locator required by the importing workflow).\n2. **Evidence** — The specific code or configuration that exhibits the issue.\n3. **What is wrong** — A clear, concrete explanation of the problem. Not \"this could be better\" but \"this does X when it should do Y\" or \"this violates [specific standard/guideline].\"\n4. **Why it matters** — Concrete impact: who is affected, what breaks, what degrades, or what standard is violated. Reference the specific standard, guideline, or documentation (e.g., WCAG 2.1 SC 4.1.2, React docs on exhaustive-deps, framework migration guide).\n5. **Suggested fix** — A concrete code change or approach, not a vague recommendation.\n\n### Verification Pass (Required)\n\nAfter gathering findings from sub-agents, verify each one yourself:\n\n1. Read the file at the cited path and confirm the line numbers are accurate.\n2. Confirm the code snippet matches what is actually in the file.\n3. Confirm the issue is real — not a false positive from misunderstanding the code's intent.\n4. Confirm the suggested fix would not break existing behavior.\n5. Drop any finding where verification fails.\n\n### Quality Gate — When to Noop\n\nCall `noop` if any of these are true:\n- No findings survive the verification pass.\n- All findings are below the severity threshold.\n- All findings are already tracked by open issues.\n- All findings are subjective style preferences rather than concrete quality issues.\n- You cannot provide specific file paths and line numbers for any finding.\n\n### Consolidation Rules\n\n- Group related findings (e.g., the same anti-pattern in multiple files) into a single numbered section.\n- Prefer fewer, denser issues over frequent thin issues.\n- If a pattern appears in many files, do a completeness pass: search the repo for all occurrences and list them, so maintainers can fix the whole family at once.\n\n### Output Contract\n\nFollow the importing workflow's issue title/body template. This shared fragment defines quality gates and evidence requirements only; per-workflow report schemas remain source-of-truth for final output format.\n\n" - GH_AW_PROMPT_CONTENT_0018: "### Data Gathering\n\n1. Understand the project:\n - Read `README.md`, `CONTRIBUTING.md`, `DEVELOPING.md`, and any docs directory.\n - Read `package.json`, `go.mod`, `pyproject.toml`, or equivalent to identify the tech stack and versions.\n - Skim the directory structure to understand the codebase layout.\n\n2. Use the **Pick Three, Keep Many** pattern for the audit:\n - Spawn 3 `general-purpose` sub-agents, each auditing from a different angle as defined in the **Audit Criteria** section below.\n - Each sub-agent prompt must include: the full audit criteria, the tech stack info, relevant file paths, and the severity threshold.\n - Each sub-agent should return all findings that meet the severity threshold, with specific file paths, line numbers, and code snippets.\n - Wait for all sub-agents to complete, then merge and deduplicate.\n\n3. Check for duplicates:\n - Read `/tmp/previous-findings.json` for issues already filed by this agent.\n - Search open issues: `repo:{owner}/{repo} is:issue is:open in:title \"__GH_AW_EXPR_BF503D80__\"`.\n - Drop any finding that closely matches an existing open issue.\n\n### Labeling\n\n- If a label matching the title prefix (without brackets) exists (check with `github-get_label`), include it in the `create_issue` call; otherwise, rely on the `__GH_AW_EXPR_BF503D80__` title prefix only.\n\n## Audit Criteria\n\n__GH_AW_EXPR_49B959F1__\n\n" + GH_AW_PROMPT_CONTENT_0018: "### Data Gathering\n\n1. Understand the project:\n - Read `README.md`, `CONTRIBUTING.md`, `DEVELOPING.md`, and any docs directory.\n - Read `package.json`, `go.mod`, `pyproject.toml`, or equivalent to identify the tech stack and versions.\n - Skim the directory structure to understand the codebase layout.\n\n2. Use the **Pick Three, Keep Many** pattern for the audit:\n - Spawn 3 `general-purpose` sub-agents, each auditing from a different angle as defined in the **Audit Criteria** section below.\n - Each sub-agent prompt must include: the full audit criteria, the tech stack info, relevant file paths, and the severity threshold.\n - Each sub-agent should return all findings that meet the severity threshold, with specific file paths, line numbers, and code snippets.\n - Wait for all sub-agents to complete, then merge and deduplicate.\n\n3. Check for duplicates:\n - Read `/tmp/previous-findings.json` for issues already filed by this agent.\n - Search open issues: `repo:__GH_AW_EXPR_596E2A60__ is:issue is:open in:title \"__GH_AW_EXPR_BF503D80__\"`.\n - Drop any finding that closely matches an existing open issue.\n\n### Labeling\n\n- If a label matching the title prefix (without brackets) exists in `__GH_AW_EXPR_596E2A60__` (check with `github-get_label`), include it in the `create_issue` call; otherwise, rely on the `__GH_AW_EXPR_BF503D80__` title prefix only.\n\n## Audit Criteria\n\n__GH_AW_EXPR_49B959F1__\n\n" with: script: | const { setupGlobals } = require(process.env.GH_AW_ACTIONS_DIR + '/setup_globals.cjs'); @@ -362,6 +368,7 @@ jobs: GH_AW_INPUTS_MODEL: ${{ inputs.model }} GH_AW_EXPR_08E89BCD: ${{ inputs.severity-threshold }} GH_AW_EXPR_49B959F1: ${{ inputs.additional-instructions }} + GH_AW_EXPR_596E2A60: ${{ inputs.target-repo }} GH_AW_EXPR_BF503D80: ${{ inputs.title-prefix }} with: script: | @@ -379,6 +386,7 @@ jobs: GH_AW_EXPR_1A3A194A: ${{ github.event.discussion.number || (fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_type == 'discussion' && fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_number) }} GH_AW_EXPR_463A214A: ${{ github.event.pull_request.number || (fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_type == 'pull_request' && fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_number) }} GH_AW_EXPR_49B959F1: ${{ inputs.additional-instructions }} + GH_AW_EXPR_596E2A60: ${{ inputs.target-repo }} GH_AW_EXPR_802A9F6A: ${{ github.event.issue.number || (fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_type == 'issue' && fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').item_number) }} GH_AW_EXPR_BF503D80: ${{ inputs.title-prefix }} GH_AW_EXPR_FF1D34CE: ${{ github.event.comment.id || fromJSON(github.event.inputs.aw_context || github.event.client_payload.aw_context || '{}').comment_id }} @@ -406,6 +414,7 @@ jobs: GH_AW_EXPR_1A3A194A: process.env.GH_AW_EXPR_1A3A194A, GH_AW_EXPR_463A214A: process.env.GH_AW_EXPR_463A214A, GH_AW_EXPR_49B959F1: process.env.GH_AW_EXPR_49B959F1, + GH_AW_EXPR_596E2A60: process.env.GH_AW_EXPR_596E2A60, GH_AW_EXPR_802A9F6A: process.env.GH_AW_EXPR_802A9F6A, GH_AW_EXPR_BF503D80: process.env.GH_AW_EXPR_BF503D80, GH_AW_EXPR_FF1D34CE: process.env.GH_AW_EXPR_FF1D34CE, @@ -617,9 +626,9 @@ jobs: github.event.pull_request || github.event.issue.pull_request || github.event_name == 'workflow_dispatch' && fromJSON(github.event.inputs.aw_context || '{}').item_type == 'pull_request' uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: - GH_TOKEN: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} + GH_TOKEN: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} with: - github-token: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} + github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} script: | const path = require('path'); const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); @@ -673,7 +682,8 @@ jobs: env: GH_AW_FILE_ROOT: "${{ runner.temp }}/gh-aw" GH_AW_FILE_CONFIG: "{\"files\":[{\"path\":\"safeoutputs/config.json\",\"content_env\":\"GH_AW_SAFE_OUTPUTS_CONFIG\"}]}" - GH_AW_SAFE_OUTPUTS_CONFIG: "{\"create_issue\":{\"close_older_issues\":false,\"close_older_key\":\"${GH_AW_INPUT_TITLE_PREFIX}\",\"expires\":168,\"max\":1,\"title_prefix\":\"${GH_AW_INPUT_TITLE_PREFIX} \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":1,\"report-as-issue\":\"true\"},\"report_incomplete\":{}}" + GH_AW_SAFE_OUTPUTS_CONFIG: "{\"create_issue\":{\"close_older_issues\":false,\"close_older_key\":\"${GH_AW_INPUT_TITLE_PREFIX}\",\"expires\":168,\"max\":1,\"target-repo\":\"${GH_AW_INPUT_TARGET_REPO}\",\"title_prefix\":\"${GH_AW_INPUT_TITLE_PREFIX} \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":1,\"report-as-issue\":\"true\"},\"report_incomplete\":{}}" + GH_AW_INPUT_TARGET_REPO: ${{ inputs.target-repo }} GH_AW_INPUT_TITLE_PREFIX: ${{ inputs.title-prefix }} with: script: | @@ -688,7 +698,7 @@ jobs: GH_AW_TOOLS_META_JSON: | { "description_suffixes": { - "create_issue": " CONSTRAINTS: Maximum 1 issue(s) can be created. Title will be prefixed with \"${GH_AW_EXPR_BF503D80} \"." + "create_issue": " CONSTRAINTS: Maximum 1 issue(s) can be created. Title will be prefixed with \"${GH_AW_EXPR_BF503D80} \". Issues will be created in repository \"${GH_AW_EXPR_596E2A60}\"." }, "repo_params": {}, "dynamic_tools": [] @@ -807,6 +817,7 @@ jobs: } } } + GH_AW_EXPR_596E2A60: ${{ inputs.target-repo }} GH_AW_EXPR_BF503D80: ${{ inputs.title-prefix }} uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: @@ -829,6 +840,7 @@ jobs: GITHUB_MCP_GUARD_REPOS: ${{ steps.determine-automatic-lockdown.outputs.repos }} GITHUB_MCP_SERVER_TOKEN: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN || secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GH_AW_INPUT_TARGET_REPO: ${{ inputs.target-repo }} GH_AW_INPUT_TITLE_PREFIX: ${{ inputs.title-prefix }} run: | set -eo pipefail @@ -856,11 +868,11 @@ jobs: MCP_GATEWAY_UID=$(id -u 2>/dev/null || echo '0') MCP_GATEWAY_GID=$(id -g 2>/dev/null || echo '0') source "${RUNNER_TEMP}/gh-aw/actions/resolve_docker_socket_gid.sh" - export MCP_GATEWAY_DOCKER_COMMAND='docker run -i --rm --network bridge -p 127.0.0.1:'"${MCP_GATEWAY_PORT}"':'"${MCP_GATEWAY_PORT}"' --name awmg-mcpg --add-host host.docker.internal:host-gateway --user '"${MCP_GATEWAY_UID}"':'"${MCP_GATEWAY_GID}"' --group-add '"${DOCKER_SOCK_GID}"' -v '"${DOCKER_SOCK_PATH}"':/var/run/docker.sock -e MCP_GATEWAY_PORT -e MCP_GATEWAY_DOMAIN -e MCP_GATEWAY_API_KEY -e MCP_GATEWAY_PAYLOAD_DIR -e MCP_GATEWAY_PAYLOAD_SIZE_THRESHOLD -e DOCKER_HOST=unix:///var/run/docker.sock -e DEBUG -e MCP_GATEWAY_LOG_DIR -e GH_AW_MCP_LOG_DIR -e GH_AW_SAFE_OUTPUTS -e GH_AW_SAFE_OUTPUTS_CONFIG_PATH -e GH_AW_SAFE_OUTPUTS_TOOLS_PATH -e GH_AW_POLICY_ALLOW_CREATE_PULL_REQUEST -e GH_AW_ASSETS_BRANCH -e GH_AW_ASSETS_MAX_SIZE_KB -e GH_AW_ASSETS_ALLOWED_EXTS -e DEFAULT_BRANCH -e GITHUB_MCP_SERVER_TOKEN -e GITHUB_MCP_GUARD_MIN_INTEGRITY -e GITHUB_MCP_GUARD_REPOS -e GH_AW_SINK_VISIBILITY -e GITHUB_REPOSITORY -e GITHUB_SERVER_URL -e GITHUB_SHA -e GITHUB_WORKSPACE -e GITHUB_TOKEN -e GITHUB_RUN_ID -e GITHUB_RUN_NUMBER -e GITHUB_RUN_ATTEMPT -e GITHUB_JOB -e GITHUB_ACTION -e GITHUB_EVENT_NAME -e GITHUB_EVENT_PATH -e GITHUB_ACTOR -e GITHUB_ACTOR_ID -e GITHUB_TRIGGERING_ACTOR -e GITHUB_WORKFLOW -e GITHUB_WORKFLOW_REF -e GITHUB_WORKFLOW_SHA -e GITHUB_REF -e GITHUB_REF_NAME -e GITHUB_REF_TYPE -e GITHUB_HEAD_REF -e GITHUB_BASE_REF -e RUNNER_TEMP -e MCP_GATEWAY_ALLOWED_MOUNT_ROOTS -e GH_AW_INPUT_TITLE_PREFIX -v /tmp/gh-aw/mcp-payloads:/tmp/gh-aw/mcp-payloads:rw -v /opt:/opt:ro -v /tmp:/tmp:rw -v '"${GITHUB_WORKSPACE}"':'"${GITHUB_WORKSPACE}"':rw -v '"${RUNNER_TEMP}"'/gh-aw/safeoutputs:'"${RUNNER_TEMP}"'/gh-aw/safeoutputs:rw ghcr.io/github/gh-aw-mcpg:v0.4.10' + export MCP_GATEWAY_DOCKER_COMMAND='docker run -i --rm --network bridge -p 127.0.0.1:'"${MCP_GATEWAY_PORT}"':'"${MCP_GATEWAY_PORT}"' --name awmg-mcpg --add-host host.docker.internal:host-gateway --user '"${MCP_GATEWAY_UID}"':'"${MCP_GATEWAY_GID}"' --group-add '"${DOCKER_SOCK_GID}"' -v '"${DOCKER_SOCK_PATH}"':/var/run/docker.sock -e MCP_GATEWAY_PORT -e MCP_GATEWAY_DOMAIN -e MCP_GATEWAY_API_KEY -e MCP_GATEWAY_PAYLOAD_DIR -e MCP_GATEWAY_PAYLOAD_SIZE_THRESHOLD -e DOCKER_HOST=unix:///var/run/docker.sock -e DEBUG -e MCP_GATEWAY_LOG_DIR -e GH_AW_MCP_LOG_DIR -e GH_AW_SAFE_OUTPUTS -e GH_AW_SAFE_OUTPUTS_CONFIG_PATH -e GH_AW_SAFE_OUTPUTS_TOOLS_PATH -e GH_AW_POLICY_ALLOW_CREATE_PULL_REQUEST -e GH_AW_ASSETS_BRANCH -e GH_AW_ASSETS_MAX_SIZE_KB -e GH_AW_ASSETS_ALLOWED_EXTS -e DEFAULT_BRANCH -e GITHUB_MCP_SERVER_TOKEN -e GITHUB_MCP_GUARD_MIN_INTEGRITY -e GITHUB_MCP_GUARD_REPOS -e GH_AW_SINK_VISIBILITY -e GITHUB_REPOSITORY -e GITHUB_SERVER_URL -e GITHUB_SHA -e GITHUB_WORKSPACE -e GITHUB_TOKEN -e GITHUB_RUN_ID -e GITHUB_RUN_NUMBER -e GITHUB_RUN_ATTEMPT -e GITHUB_JOB -e GITHUB_ACTION -e GITHUB_EVENT_NAME -e GITHUB_EVENT_PATH -e GITHUB_ACTOR -e GITHUB_ACTOR_ID -e GITHUB_TRIGGERING_ACTOR -e GITHUB_WORKFLOW -e GITHUB_WORKFLOW_REF -e GITHUB_WORKFLOW_SHA -e GITHUB_REF -e GITHUB_REF_NAME -e GITHUB_REF_TYPE -e GITHUB_HEAD_REF -e GITHUB_BASE_REF -e RUNNER_TEMP -e MCP_GATEWAY_ALLOWED_MOUNT_ROOTS -e GH_AW_INPUT_TARGET_REPO -e GH_AW_INPUT_TITLE_PREFIX -v /tmp/gh-aw/mcp-payloads:/tmp/gh-aw/mcp-payloads:rw -v /opt:/opt:ro -v /tmp:/tmp:rw -v '"${GITHUB_WORKSPACE}"':'"${GITHUB_WORKSPACE}"':rw -v '"${RUNNER_TEMP}"'/gh-aw/safeoutputs:'"${RUNNER_TEMP}"'/gh-aw/safeoutputs:rw ghcr.io/github/gh-aw-mcpg:v0.4.10' mkdir -p "$HOME/.copilot" GH_AW_NODE=$(which node 2>/dev/null || command -v node 2>/dev/null || echo node) - cat << GH_AW_MCP_CONFIG_6425d490c31a2514_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" + cat << GH_AW_MCP_CONFIG_ef6ec932ad288dce_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs" { "mcpServers": { "github": { @@ -920,6 +932,7 @@ jobs: "GITHUB_TOKEN": "\${GITHUB_TOKEN}", "GITHUB_WORKSPACE": "\${GITHUB_WORKSPACE}", "RUNNER_TEMP": "\${RUNNER_TEMP}", + "GH_AW_INPUT_TARGET_REPO": "\${GH_AW_INPUT_TARGET_REPO}", "GH_AW_INPUT_TITLE_PREFIX": "\${GH_AW_INPUT_TITLE_PREFIX}" }, "guard-policies": { @@ -940,7 +953,7 @@ jobs: "startupTimeout": 120 } } - GH_AW_MCP_CONFIG_6425d490c31a2514_EOF + GH_AW_MCP_CONFIG_ef6ec932ad288dce_EOF - name: Mount MCP servers as CLIs id: mount-mcp-clis continue-on-error: true @@ -1020,6 +1033,7 @@ jobs: COPILOT_DUMMY_BYOK: dummy-byok-key-for-offline-mode COPILOT_GITHUB_TOKEN: ${{ github.token }} COPILOT_MODEL: ${{ inputs.model }} + GH_AW_INPUT_TARGET_REPO: ${{ inputs.target-repo }} GH_AW_INPUT_TITLE_PREFIX: ${{ inputs.title-prefix }} GH_AW_LLM_PROVIDER: github GH_AW_MAX_AI_CREDITS: ${{ vars.GH_AW_DEFAULT_MAX_AI_CREDITS || '1000' }} @@ -1900,7 +1914,7 @@ jobs: GH_AW_ALLOWED_DOMAINS: "*.docker.com,*.docker.io,*.githubusercontent.com,*.gradle-enterprise.cloud,*.hackage.haskell.org,*.pythonhosted.org,*.rvm.io,*.vsblob.vsassets.io,adoptium.net,agents-md-generator.fastmcp.app,anaconda.org,api.adoptium.net,api.business.githubcopilot.com,api.enterprise.githubcopilot.com,api.foojay.io,api.github.com,api.githubcopilot.com,api.individual.githubcopilot.com,api.npms.io,api.nuget.org,api.rubygems.org,api.snapcraft.io,apt.llvm.org,apt.releases.hashicorp.com,archive.apache.org,archive.ubuntu.com,archlinux.org,artifacts.elastic.co,auth.docker.io,azure.archive.ubuntu.com,azuresearch-usnc.nuget.org,azuresearch-ussc.nuget.org,binstar.org,bitbucket.org,bootstrap.pypa.io,builds.dotnet.microsoft.com,builds.hex.pm,bun.sh,bundler.rubygems.org,cache.ruby-lang.org,cdn.azul.com,cdn.cocoapods.org,cdn.hex.pm,cdn.jsdelivr.net,cdn.playwright.dev,cdn.redhat.com,cdn.sheetjs.com,central.sonatype.com,ci.dot.net,clojars.org,cloud.elastic.co,cocoapods.org,code.jquery.com,codeload.github.com,conda.anaconda.org,conda.binstar.org,cpan.metacpan.org,cpan.org,crates.io,crl.geotrust.com,crl.globalsign.com,crl.identrust.com,crl.sectigo.com,crl.thawte.com,crl.usertrust.com,crl.verisign.com,crl3.digicert.com,crl4.digicert.com,crls.ssl.com,data.jsdelivr.com,dc.services.visualstudio.com,deb.debian.org,deb.nodesource.com,debian.map.fastlydns.net,deno.land,deps.files.ghostty.org,develocity.apache.org,dist.nuget.org,dl-cdn.alpinelinux.org,dl.bintray.com,dl.fedoraproject.org,dl.google.com,dl.k8s.io,dlcdn.apache.org,docs.github.com,dot.net,dotnet.microsoft.com,dotnetcli.blob.core.windows.net,download.eclipse.org,download.fedoraproject.org,download.java.net,download.jetbrains.com,download.opensuse.org,download.oracle.com,download.swift.org,downloads.gradle-dn.com,downloads.haskell.org,ela.st,elastic.co,elastic.dev,elastic.github.io,esm.sh,fastly.hex.pm,files.pythonhosted.org,fonts.googleapis.com,fonts.gstatic.com,gcr.io,ge.jetbrains.com,ge.spockframework.org,gems.rubyforge.org,gems.rubyonrails.org,get-ghcup.haskell.org,get.pnpm.io,getcomposer.org,ghcr.io,github-cloud.githubusercontent.com,github-cloud.s3.amazonaws.com,github.blog,github.com,github.githubassets.com,go.dev,golang.org,googleapis.deno.dev,googlechromelabs.github.io,goproxy.io,gradle.org,haskell.org,hex.pm,host.docker.internal,index.crates.io,index.rubygems.org,jcenter.bintray.com,jdk.java.net,jitpack.io,json-schema.org,json.schemastore.org,jsr.io,keyring.debian.org,keyserver.ubuntu.com,kotlin.bintray.com,lfs.github.com,maven-central.storage-download.googleapis.com,maven.apache.org,maven.google.com,maven.oracle.com,maven.pkg.github.com,maven.pkg.jetbrains.space,mcr.microsoft.com,metacpan.org,mirror.archlinux.org,mirror.centos.org,mirrors.fedoraproject.org,nodejs.org,npm.pkg.github.com,npmjs.com,npmjs.org,nuget.org,nuget.pkg.github.com,nugetregistryv2prod.blob.core.windows.net,objects.githubusercontent.com,ocsp.digicert.com,ocsp.geotrust.com,ocsp.globalsign.com,ocsp.identrust.com,ocsp.sectigo.com,ocsp.ssl.com,ocsp.thawte.com,ocsp.usertrust.com,ocsp.verisign.com,oneocsp.microsoft.com,packagecloud.io,packages.cloud.google.com,packages.debian.org,packages.jetbrains.team,packages.microsoft.com,packagist.org,patch-diff.githubusercontent.com,patchdiff.githubusercontent.com,pip.pypa.io,pkg.alpinelinux.org,pkg.go.dev,pkg.machengine.org,pkgs.dev.azure.com,pkgs.k8s.io,playwright.download.prss.microsoft.com,plugins-artifacts.gradle.org,plugins.gradle.org,ppa.launchpad.net,production.cloudflare.docker.com,productionresultssa0.blob.core.windows.net,productionresultssa1.blob.core.windows.net,productionresultssa10.blob.core.windows.net,productionresultssa11.blob.core.windows.net,productionresultssa12.blob.core.windows.net,productionresultssa13.blob.core.windows.net,productionresultssa14.blob.core.windows.net,productionresultssa15.blob.core.windows.net,productionresultssa16.blob.core.windows.net,productionresultssa17.blob.core.windows.net,productionresultssa18.blob.core.windows.net,productionresultssa19.blob.core.windows.net,productionresultssa2.blob.core.windows.net,productionresultssa3.blob.core.windows.net,productionresultssa4.blob.core.windows.net,productionresultssa5.blob.core.windows.net,productionresultssa6.blob.core.windows.net,productionresultssa7.blob.core.windows.net,productionresultssa8.blob.core.windows.net,productionresultssa9.blob.core.windows.net,proxy.golang.org,pub.dartlang.org,pub.dev,public-code-search.fastmcp.app,pypi.org,pypi.python.org,quay.io,raw.githubusercontent.com,registry.bower.io,registry.hub.docker.com,registry.npmjs.com,registry.npmjs.org,registry.terraform.io,registry.yarnpkg.com,releases.hashicorp.com,repo.anaconda.com,repo.clojars.org,repo.continuum.io,repo.gradle.org,repo.grails.org,repo.hex.pm,repo.maven.apache.org,repo.packagist.org,repo.scala-sbt.org,repo.spring.io,repo.typesafe.com,repo.yarnpkg.com,repo1.maven.org,repository.apache.org,rubygems.org,rubygems.pkg.github.com,s.symcb.com,s.symcd.com,scala-ci.typesafe.com,scala.jfrog.io,scans-in.gradle.com,security.debian.org,security.ubuntu.com,services.gradle.org,sh.rustup.rs,skimdb.npmjs.com,static.crates.io,static.rust-lang.org,storage.googleapis.com,sum.golang.org,swift.org,telemetry.enterprise.githubcopilot.com,telemetry.vercel.com,ts-crl.ws.symantec.com,ts-ocsp.ws.symantec.com,vault.centos.org,www.cpan.org,www.elastic.co,www.googleapis.com,www.java.com,www.microsoft.com,www.npmjs.com,www.npmjs.org,yarnpkg.com,yum.releases.hashicorp.com,ziglang.org" GITHUB_SERVER_URL: ${{ github.server_url }} GITHUB_API_URL: ${{ github.api_url }} - GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"create_issue\":{\"close_older_issues\":false,\"close_older_key\":\"${{ inputs.title-prefix }}\",\"expires\":168,\"max\":1,\"title_prefix\":\"${{ inputs.title-prefix }} \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":1,\"report-as-issue\":\"true\"},\"report_incomplete\":{}}" + GH_AW_SAFE_OUTPUTS_HANDLER_CONFIG: "{\"create_issue\":{\"close_older_issues\":false,\"close_older_key\":\"${{ inputs.title-prefix }}\",\"expires\":168,\"max\":1,\"target-repo\":\"${{ inputs.target-repo }}\",\"title_prefix\":\"${{ inputs.title-prefix }} \"},\"create_report_incomplete_issue\":{},\"missing_data\":{},\"missing_tool\":{},\"noop\":{\"max\":1,\"report-as-issue\":\"true\"},\"report_incomplete\":{}}" with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} script: | diff --git a/.github/workflows/gh-aw-code-quality-audit.md b/.github/workflows/gh-aw-code-quality-audit.md index 5760d975..0a1bed9c 100644 --- a/.github/workflows/gh-aw-code-quality-audit.md +++ b/.github/workflows/gh-aw-code-quality-audit.md @@ -51,6 +51,11 @@ on: description: "Title prefix for created issues (e.g. '[react-accessibility]')" type: string required: true + target-repo: + description: "Repository where audit issues are created, in owner/repo format. Defaults to the workflow repository; use GH_AW_GITHUB_TOKEN for cross-repository access." + type: string + required: false + default: "${{ github.repository }}" severity-threshold: description: "Minimum severity to include in the report. 'high' = only report issues with clear user impact or correctness problems. 'medium' (default) = also include issues that degrade quality or maintainability. 'low' = also include minor deviations from best practices." type: string @@ -61,6 +66,9 @@ on: type: boolean required: false default: true + secrets: + GH_AW_GITHUB_TOKEN: + required: false roles: [admin, maintainer, write] bots: - "${{ inputs.allowed-bot-users }}" @@ -81,9 +89,11 @@ tools: strict: false safe-outputs: activation-comments: false + github-token: "${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}" noop: create-issue: max: 1 + target-repo: "${{ inputs.target-repo }}" title-prefix: "${{ inputs.title-prefix }} " close-older-key: "${{ inputs.title-prefix }}" close-older-issues: false @@ -125,12 +135,12 @@ steps: 3. Check for duplicates: - Read `/tmp/previous-findings.json` for issues already filed by this agent. - - Search open issues: `repo:{owner}/{repo} is:issue is:open in:title "${{ inputs.title-prefix }}"`. + - Search open issues: `repo:${{ inputs.target-repo }} is:issue is:open in:title "${{ inputs.title-prefix }}"`. - Drop any finding that closely matches an existing open issue. ### Labeling -- If a label matching the title prefix (without brackets) exists (check with `github-get_label`), include it in the `create_issue` call; otherwise, rely on the `${{ inputs.title-prefix }}` title prefix only. +- If a label matching the title prefix (without brackets) exists in `${{ inputs.target-repo }}` (check with `github-get_label`), include it in the `create_issue` call; otherwise, rely on the `${{ inputs.title-prefix }}` title prefix only. ## Audit Criteria